Skip to content

[pull] master from php:master - #1294

Merged
pull[bot] merged 46 commits into
turkdevops:masterfrom
php:master
Sep 22, 2026
Merged

pull[bot] merged 46 commits into
turkdevops:masterfrom
php:master

Conversation

@pull

@pull pull Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

geeknik and others added 30 commits September 18, 2026 17:06
…reak-chars

Use pestrndup() instead of pestrdup() when duplicating lbchars in the
base64-encode, quoted-printable-encode, and quoted-printable-decode
filter constructors. pestrdup() is strlen-based and truncates at the
first NUL byte, but lbchars_len preserves the original length, causing
an out-of-bounds read when the filter later copies lbchars_len bytes
from the truncated allocation.

Fixes GHSA-88hq-2827-7pg6.
…vice ID

RFC 6125 6.4.4 forbids matching CN-ID if the certificate presents a DNS-ID,
SRV-ID or URI-ID. Falling back allowed a CA that validated only one of those
identities to leave an unvalidated CN to be matched as a host name.

IP-ID is left out as it is out of scope of RFC 6125 and suppressing CN there
would break IP-only SAN certificates.
The memchr() length underflowed when the wildcard prefix and suffix
overlapped in the subject name (e.g. CN "a*aaaa" against peer name "aaaa").
…ocol

Co-authored-by: Nora Dossche <7771979+ndossche@users.noreply.github.com>
…-origin redirects

Authorization, Cookie and Proxy-Authorization set through the http context
were forwarded verbatim when follow_location sent the request to another
origin. They are now stripped from the user header bag whenever the
redirect target differs in scheme, host or port, including when the header
name is repeated or the bag uses malformed line endings.

Co-authored-by: Jakub Zelenka <bukka@php.net>
Co-authored-by: Jakub Zelenka <bukka@php.net>
Reject entry sizes that cannot be parsed or represented, and skip the data
blocks of every entry type that carries data. Both left the stream on
attacker controlled data that was then parsed as a tar header.
Reject Windows reserved device names (CON, NUL, COM1, ...) used as a path
component in filesystem operations. Bare device names and DOS device
paths keep working.

Co-authored-by: Jakub Zelenka <bukka@php.net>
php_filter_encode_url() initialized its 256-byte "must encode" table with
memset(tmp, 1, sizeof(tmp) - 1), leaving tmp[255] uninitialized. Whether
0xFF got percent-encoded then depended on stack garbage; valgrind reports
the read as a conditional jump on an uninitialised value. Initialize the
whole table.

Backport of 5614918 from PHP-8.4.
An empty Location header allocates a single byte for the NUL
terminator, so reading location[1] in the relative-redirect branch
over-reads heap memory and could append a garbage-derived path to the
redirect target instead of the correct host root. Use location_len
instead of strlen, and skip the relative join when location_len is 0,
so the second byte is never read.

Closes GH-23467
8196275 changed the relative-Location check from location_len > 1 to
> 0, so a single-character Location began resolving against the request
path instead of the host root as before.

Closes GH-23521
The regression test for GHSA-cj93-vc83-wgqv sends a 2 GiB chunked body so
that the client-side 32-bit length arithmetic overflows. Building that
body as a PHP string and wrapping it in a data:// stream materialised the
payload several times (str_repeat, concatenation, and the data:// copy),
and those buffers lingered in the client process after the fork. Total
footprint reached ~8 GiB and the run took ~16s locally, far more under
slower/opcache CI jobs where it swapped and hit the run-tests timeout.

Replace the generic http_server() helper with a minimal server that
streams the 2 GiB filler in 8 MiB blocks. The bytes the client sees are
identical, so the code path under test is unchanged, but the sender's
memory stays small: only the client holds the large buffers (~4 GiB).
Run time drops to ~4s and peak memory roughly halves.

Also raise the free-RAM skip threshold from 4G to 6G to match the ~4 GiB
the client actually allocates, so the test skips rather than swaps on
memory-constrained machines.
The test assumes that IPv4 multicast is available. In an isolated Linux
network namespace, joining the group fails before the test starts.

Probe that capability in SKIPIF and skip the test when it is unavailable.

Close GH-23838
* PHP-8.4:
  Fix GH-11662: Skip multicast test when unavailable
* PHP-8.5:
  Fix GH-11662: Skip multicast test when unavailable
* PHP-8.2:
  ext/soap: make GHSA-cj93-vc83-wgqv test lean and reliable
  Add NEWS entries
  ext/standard: Fix 1-char relative Location redirects after GH-23467
  [http] Fix out-of-bounds read on empty Location header
  Fix GHSA-ch8v-r6jh-4vvr: encode 0xFF in FILTER_SANITIZE_ENCODED
  Fix GHSA-9f67-6fw4-hpfp
  Fix GHSA-j3wh-g957-2m85: phar tar entry injection
  Fix GHSA-cj93-vc83-wgqv
  Fix GHSA-rgrp-mwpx-f6rm: unbounded recursion in ext/soap XML parsing and decoding
  Fix GHSA-fpwc-w8rq-cr92: strip credentials from user headers on cross-origin redirects
  Fix GHSA-r6x9-5r99-36j7: Various packet overreads in mysqlnd wireprotocol
  Fix GHSA-xr7j-rvgx-xq5p: OOB read in php_openssl_matches_wildcard_name()
  Fix GHSA-vvx9-73fr-5jjx: do not fall back to CN if the cert has a service ID
  Fix GHSA-62xp-839h-2637: FastCGI allowed_clients compared only 96 bits of IPv6 addresses
  Fix heap-buffer-overflow in convert stream filters with NUL in line-break-chars
* PHP-8.3:
  ext/soap: make GHSA-cj93-vc83-wgqv test lean and reliable
  Add NEWS entries
  ext/standard: Fix 1-char relative Location redirects after GH-23467
  [http] Fix out-of-bounds read on empty Location header
  Fix GHSA-ch8v-r6jh-4vvr: encode 0xFF in FILTER_SANITIZE_ENCODED
  Fix GHSA-9f67-6fw4-hpfp
  Fix GHSA-j3wh-g957-2m85: phar tar entry injection
  Fix GHSA-cj93-vc83-wgqv
  Fix GHSA-rgrp-mwpx-f6rm: unbounded recursion in ext/soap XML parsing and decoding
  Fix GHSA-fpwc-w8rq-cr92: strip credentials from user headers on cross-origin redirects
  Fix GHSA-r6x9-5r99-36j7: Various packet overreads in mysqlnd wireprotocol
  Fix GHSA-xr7j-rvgx-xq5p: OOB read in php_openssl_matches_wildcard_name()
  Fix GHSA-vvx9-73fr-5jjx: do not fall back to CN if the cert has a service ID
  Fix GHSA-62xp-839h-2637: FastCGI allowed_clients compared only 96 bits of IPv6 addresses
  Fix heap-buffer-overflow in convert stream filters with NUL in line-break-chars

# Conflicts:
#	ext/openssl/xp_ssl.c
The decompressed output of this test peaks at more than 12 GiB of RSS.
On smaller machines, such as the 7 GB GitHub-hosted runners used for
private repositories, this exhausts the whole VM and the OOM killer takes
the test runner down with it, so the job dies with a runner shutdown
signal instead of a test failure.

Gate the test on MemAvailable from /proc/meminfo like the other
resource-heavy tests gate on memory, so it keeps running on the 16 GB
public runners and skips itself elsewhere.
* PHP-8.4:
  Skip bz2 GH-20807 test when less than 13 GiB of memory is available
  ext/soap: make GHSA-cj93-vc83-wgqv test lean and reliable
  Add NEWS entries
  ext/standard: Fix 1-char relative Location redirects after GH-23467
  [http] Fix out-of-bounds read on empty Location header
  Fix GHSA-ch8v-r6jh-4vvr: encode 0xFF in FILTER_SANITIZE_ENCODED
  Fix GHSA-9f67-6fw4-hpfp
  Fix GHSA-j3wh-g957-2m85: phar tar entry injection
  Fix GHSA-cj93-vc83-wgqv
  Fix GHSA-rgrp-mwpx-f6rm: unbounded recursion in ext/soap XML parsing and decoding
  Fix GHSA-fpwc-w8rq-cr92: strip credentials from user headers on cross-origin redirects
  Fix GHSA-r6x9-5r99-36j7: Various packet overreads in mysqlnd wireprotocol
  Fix GHSA-xr7j-rvgx-xq5p: OOB read in php_openssl_matches_wildcard_name()
  Fix GHSA-vvx9-73fr-5jjx: do not fall back to CN if the cert has a service ID
  Fix GHSA-62xp-839h-2637: FastCGI allowed_clients compared only 96 bits of IPv6 addresses
  Fix heap-buffer-overflow in convert stream filters with NUL in line-break-chars

# Conflicts:
#	NEWS
#	ext/phar/tar.c
#	ext/soap/php_http.c
#	ext/soap/php_xml.c
#	ext/standard/http_fopen_wrapper.c
#	win32/ioutil.c
* PHP-8.5:
  Skip bz2 GH-20807 test when less than 13 GiB of memory is available
  ext/soap: make GHSA-cj93-vc83-wgqv test lean and reliable
  Add NEWS entries
  ext/standard: Fix 1-char relative Location redirects after GH-23467
  [http] Fix out-of-bounds read on empty Location header
  Fix GHSA-ch8v-r6jh-4vvr: encode 0xFF in FILTER_SANITIZE_ENCODED
  Fix GHSA-9f67-6fw4-hpfp
  Fix GHSA-j3wh-g957-2m85: phar tar entry injection
  Fix GHSA-cj93-vc83-wgqv
  Fix GHSA-rgrp-mwpx-f6rm: unbounded recursion in ext/soap XML parsing and decoding
  Fix GHSA-fpwc-w8rq-cr92: strip credentials from user headers on cross-origin redirects
  Fix GHSA-r6x9-5r99-36j7: Various packet overreads in mysqlnd wireprotocol
  Fix GHSA-xr7j-rvgx-xq5p: OOB read in php_openssl_matches_wildcard_name()
  Fix GHSA-vvx9-73fr-5jjx: do not fall back to CN if the cert has a service ID
  Fix GHSA-62xp-839h-2637: FastCGI allowed_clients compared only 96 bits of IPv6 addresses
  Fix heap-buffer-overflow in convert stream filters with NUL in line-break-chars

# Conflicts:
#	NEWS
#	ext/openssl/xp_ssl.c
#	ext/phar/tar.c
#	ext/soap/php_http.c
#	ext/standard/http_fopen_wrapper.c
…hods

Collator::getAttribute(), setAttribute(), getStrength() and setStrength()
dereferenced a NULL ICU collator when called on an object whose constructor
skipped parent::__construct(), returning bogus values instead of failing,
while compare(), getLocale(), sort() and getSortKey() already throw
"Object not initialized". Apply the same guard to the four remaining
methods through a collator_check_initialized() helper, which also replaces
four existing copies.

Closes GH-23797
* PHP-8.4:
  ext/intl: Reject unconstructed Collator in attribute and strength methods
* PHP-8.5:
  ext/intl: Reject unconstructed Collator in attribute and strength methods
* PHP-8.6:
  ext/intl: Reject unconstructed Collator in attribute and strength methods
mbeccati and others added 16 commits September 22, 2026 14:48
* PHP-8.4:
  CI updates after forking 8.6
* PHP-8.5:
  CI updates after forking 8.6
* PHP-8.6:
  CI updates after forking 8.6
* PHP-8.3:
  PHP 8.3 is now for PHP 8.3.36
* PHP-8.4:
  PHP 8.3 is now for PHP 8.3.36
* PHP-8.5:
  PHP 8.3 is now for PHP 8.3.36
* PHP-8.6:
  PHP 8.3 is now for PHP 8.3.36
…the last user header

Port the line-aware strip_header() from the PHP-8.2 fix. When the stripped
header was the last line of the user header bag, the previous implementation
left the line break in front of it behind, and the CRLF appended after the bag
then ended the header block early. With Authorization, Cookie or
Proxy-Authorization now being stripped on cross-origin redirects, this could
hit a body-preserving 307/308 POST: the target received a header block cut off
after the preceding header and the wrong bytes as the body.

The ported version also removes folded continuation lines of the stripped
header and tolerates whitespace before the colon, so a header written as
"Authorization : ..." cannot slip through.
* PHP-8.5:
  Fix GHSA-fpwc-w8rq-cr92: do not cut the request short when stripping the last user header
* PHP-8.6:
  Fix GHSA-fpwc-w8rq-cr92: do not cut the request short when stripping the last user header
* PHP-8.4:
  CI updates after forking 8.6
* PHP-8.5:
  CI updates after forking 8.6
* PHP-8.6:
  CI updates after forking 8.6
@pull pull Bot locked and limited conversation to collaborators Sep 22, 2026
@pull pull Bot added the ⤵️ pull label Sep 22, 2026
@pull
pull Bot merged commit a26f9e5 into turkdevops:master Sep 22, 2026
0 of 2 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.