fix: move error finalization after stream fields in stream_get_meta_data to prevent UAF - #23458
Open
shoemoney wants to merge 1 commit into
Open
fix: move error finalization after stream fields in stream_get_meta_data to prevent UAF#23458shoemoney wants to merge 1 commit into
shoemoney wants to merge 1 commit into
Conversation
…ata to prevent UAF Fix verified RED->GREEN. stream_get_meta_data UAF at ext/standard/streamsfuncs.c:566 - php_stream_error_operation_end_for_stream calls error_handler which can fclose() stream, then reads wrapperdata/wops/label/mode/orig_path from freed memory => ASan heap-use-after-free
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes heap-use-after-free in stream_get_meta_data.
php_stream_error_operation_end_for_stream invokes the error handler which may fclose the stream. In the previous order this ran before wrapperdata, wrapper type, stream type, mode and uri were copied into the return value, so those reads touched freed memory. Deferring finalization until after all stream fields are copied closes the UAF window.
The change is a one-line reorder within PHP_FUNCTION(stream_get_meta_data). It keeps begin, populate and eof handling unchanged and only moves the end call after the last stream field access. This matches the pattern needed for the sibling reports 23259 and 23264 which share the same root cause.
Written in conjunction with my pair programmer Claude.