[pull] master from php:master - #1294
Merged
Merged
Conversation
…reak-chars Use pestrndup() instead of pestrdup() when duplicating lbchars in the base64-encode, quoted-printable-encode, and quoted-printable-decode filter constructors. pestrdup() is strlen-based and truncates at the first NUL byte, but lbchars_len preserves the original length, causing an out-of-bounds read when the filter later copies lbchars_len bytes from the truncated allocation. Fixes GHSA-88hq-2827-7pg6.
…s of IPv6 addresses
…vice ID RFC 6125 6.4.4 forbids matching CN-ID if the certificate presents a DNS-ID, SRV-ID or URI-ID. Falling back allowed a CA that validated only one of those identities to leave an unvalidated CN to be matched as a host name. IP-ID is left out as it is out of scope of RFC 6125 and suppressing CN there would break IP-only SAN certificates.
The memchr() length underflowed when the wildcard prefix and suffix overlapped in the subject name (e.g. CN "a*aaaa" against peer name "aaaa").
…ocol Co-authored-by: Nora Dossche <7771979+ndossche@users.noreply.github.com>
…-origin redirects Authorization, Cookie and Proxy-Authorization set through the http context were forwarded verbatim when follow_location sent the request to another origin. They are now stripped from the user header bag whenever the redirect target differs in scheme, host or port, including when the header name is repeated or the bag uses malformed line endings. Co-authored-by: Jakub Zelenka <bukka@php.net>
Co-authored-by: Jakub Zelenka <bukka@php.net>
Reject entry sizes that cannot be parsed or represented, and skip the data blocks of every entry type that carries data. Both left the stream on attacker controlled data that was then parsed as a tar header.
Reject Windows reserved device names (CON, NUL, COM1, ...) used as a path component in filesystem operations. Bare device names and DOS device paths keep working. Co-authored-by: Jakub Zelenka <bukka@php.net>
php_filter_encode_url() initialized its 256-byte "must encode" table with memset(tmp, 1, sizeof(tmp) - 1), leaving tmp[255] uninitialized. Whether 0xFF got percent-encoded then depended on stack garbage; valgrind reports the read as a conditional jump on an uninitialised value. Initialize the whole table. Backport of 5614918 from PHP-8.4.
An empty Location header allocates a single byte for the NUL terminator, so reading location[1] in the relative-redirect branch over-reads heap memory and could append a garbage-derived path to the redirect target instead of the correct host root. Use location_len instead of strlen, and skip the relative join when location_len is 0, so the second byte is never read. Closes GH-23467
The regression test for GHSA-cj93-vc83-wgqv sends a 2 GiB chunked body so that the client-side 32-bit length arithmetic overflows. Building that body as a PHP string and wrapping it in a data:// stream materialised the payload several times (str_repeat, concatenation, and the data:// copy), and those buffers lingered in the client process after the fork. Total footprint reached ~8 GiB and the run took ~16s locally, far more under slower/opcache CI jobs where it swapped and hit the run-tests timeout. Replace the generic http_server() helper with a minimal server that streams the 2 GiB filler in 8 MiB blocks. The bytes the client sees are identical, so the code path under test is unchanged, but the sender's memory stays small: only the client holds the large buffers (~4 GiB). Run time drops to ~4s and peak memory roughly halves. Also raise the free-RAM skip threshold from 4G to 6G to match the ~4 GiB the client actually allocates, so the test skips rather than swaps on memory-constrained machines.
The test assumes that IPv4 multicast is available. In an isolated Linux network namespace, joining the group fails before the test starts. Probe that capability in SKIPIF and skip the test when it is unavailable. Close GH-23838
* PHP-8.4: Fix GH-11662: Skip multicast test when unavailable
* PHP-8.5: Fix GH-11662: Skip multicast test when unavailable
* PHP-8.2: ext/soap: make GHSA-cj93-vc83-wgqv test lean and reliable Add NEWS entries ext/standard: Fix 1-char relative Location redirects after GH-23467 [http] Fix out-of-bounds read on empty Location header Fix GHSA-ch8v-r6jh-4vvr: encode 0xFF in FILTER_SANITIZE_ENCODED Fix GHSA-9f67-6fw4-hpfp Fix GHSA-j3wh-g957-2m85: phar tar entry injection Fix GHSA-cj93-vc83-wgqv Fix GHSA-rgrp-mwpx-f6rm: unbounded recursion in ext/soap XML parsing and decoding Fix GHSA-fpwc-w8rq-cr92: strip credentials from user headers on cross-origin redirects Fix GHSA-r6x9-5r99-36j7: Various packet overreads in mysqlnd wireprotocol Fix GHSA-xr7j-rvgx-xq5p: OOB read in php_openssl_matches_wildcard_name() Fix GHSA-vvx9-73fr-5jjx: do not fall back to CN if the cert has a service ID Fix GHSA-62xp-839h-2637: FastCGI allowed_clients compared only 96 bits of IPv6 addresses Fix heap-buffer-overflow in convert stream filters with NUL in line-break-chars
* PHP-8.3: ext/soap: make GHSA-cj93-vc83-wgqv test lean and reliable Add NEWS entries ext/standard: Fix 1-char relative Location redirects after GH-23467 [http] Fix out-of-bounds read on empty Location header Fix GHSA-ch8v-r6jh-4vvr: encode 0xFF in FILTER_SANITIZE_ENCODED Fix GHSA-9f67-6fw4-hpfp Fix GHSA-j3wh-g957-2m85: phar tar entry injection Fix GHSA-cj93-vc83-wgqv Fix GHSA-rgrp-mwpx-f6rm: unbounded recursion in ext/soap XML parsing and decoding Fix GHSA-fpwc-w8rq-cr92: strip credentials from user headers on cross-origin redirects Fix GHSA-r6x9-5r99-36j7: Various packet overreads in mysqlnd wireprotocol Fix GHSA-xr7j-rvgx-xq5p: OOB read in php_openssl_matches_wildcard_name() Fix GHSA-vvx9-73fr-5jjx: do not fall back to CN if the cert has a service ID Fix GHSA-62xp-839h-2637: FastCGI allowed_clients compared only 96 bits of IPv6 addresses Fix heap-buffer-overflow in convert stream filters with NUL in line-break-chars # Conflicts: # ext/openssl/xp_ssl.c
The decompressed output of this test peaks at more than 12 GiB of RSS. On smaller machines, such as the 7 GB GitHub-hosted runners used for private repositories, this exhausts the whole VM and the OOM killer takes the test runner down with it, so the job dies with a runner shutdown signal instead of a test failure. Gate the test on MemAvailable from /proc/meminfo like the other resource-heavy tests gate on memory, so it keeps running on the 16 GB public runners and skips itself elsewhere.
* PHP-8.4: Skip bz2 GH-20807 test when less than 13 GiB of memory is available ext/soap: make GHSA-cj93-vc83-wgqv test lean and reliable Add NEWS entries ext/standard: Fix 1-char relative Location redirects after GH-23467 [http] Fix out-of-bounds read on empty Location header Fix GHSA-ch8v-r6jh-4vvr: encode 0xFF in FILTER_SANITIZE_ENCODED Fix GHSA-9f67-6fw4-hpfp Fix GHSA-j3wh-g957-2m85: phar tar entry injection Fix GHSA-cj93-vc83-wgqv Fix GHSA-rgrp-mwpx-f6rm: unbounded recursion in ext/soap XML parsing and decoding Fix GHSA-fpwc-w8rq-cr92: strip credentials from user headers on cross-origin redirects Fix GHSA-r6x9-5r99-36j7: Various packet overreads in mysqlnd wireprotocol Fix GHSA-xr7j-rvgx-xq5p: OOB read in php_openssl_matches_wildcard_name() Fix GHSA-vvx9-73fr-5jjx: do not fall back to CN if the cert has a service ID Fix GHSA-62xp-839h-2637: FastCGI allowed_clients compared only 96 bits of IPv6 addresses Fix heap-buffer-overflow in convert stream filters with NUL in line-break-chars # Conflicts: # NEWS # ext/phar/tar.c # ext/soap/php_http.c # ext/soap/php_xml.c # ext/standard/http_fopen_wrapper.c # win32/ioutil.c
* PHP-8.5: Skip bz2 GH-20807 test when less than 13 GiB of memory is available ext/soap: make GHSA-cj93-vc83-wgqv test lean and reliable Add NEWS entries ext/standard: Fix 1-char relative Location redirects after GH-23467 [http] Fix out-of-bounds read on empty Location header Fix GHSA-ch8v-r6jh-4vvr: encode 0xFF in FILTER_SANITIZE_ENCODED Fix GHSA-9f67-6fw4-hpfp Fix GHSA-j3wh-g957-2m85: phar tar entry injection Fix GHSA-cj93-vc83-wgqv Fix GHSA-rgrp-mwpx-f6rm: unbounded recursion in ext/soap XML parsing and decoding Fix GHSA-fpwc-w8rq-cr92: strip credentials from user headers on cross-origin redirects Fix GHSA-r6x9-5r99-36j7: Various packet overreads in mysqlnd wireprotocol Fix GHSA-xr7j-rvgx-xq5p: OOB read in php_openssl_matches_wildcard_name() Fix GHSA-vvx9-73fr-5jjx: do not fall back to CN if the cert has a service ID Fix GHSA-62xp-839h-2637: FastCGI allowed_clients compared only 96 bits of IPv6 addresses Fix heap-buffer-overflow in convert stream filters with NUL in line-break-chars # Conflicts: # NEWS # ext/openssl/xp_ssl.c # ext/phar/tar.c # ext/soap/php_http.c # ext/standard/http_fopen_wrapper.c
…hods Collator::getAttribute(), setAttribute(), getStrength() and setStrength() dereferenced a NULL ICU collator when called on an object whose constructor skipped parent::__construct(), returning bogus values instead of failing, while compare(), getLocale(), sort() and getSortKey() already throw "Object not initialized". Apply the same guard to the four remaining methods through a collator_check_initialized() helper, which also replaces four existing copies. Closes GH-23797
* PHP-8.4: ext/intl: Reject unconstructed Collator in attribute and strength methods
* PHP-8.5: ext/intl: Reject unconstructed Collator in attribute and strength methods
* PHP-8.6: ext/intl: Reject unconstructed Collator in attribute and strength methods
* PHP-8.4: CI updates after forking 8.6
* PHP-8.5: CI updates after forking 8.6
* PHP-8.6: CI updates after forking 8.6
* PHP-8.3: PHP 8.3 is now for PHP 8.3.36
* PHP-8.4: PHP 8.3 is now for PHP 8.3.36
* PHP-8.5: PHP 8.3 is now for PHP 8.3.36
* PHP-8.6: PHP 8.3 is now for PHP 8.3.36
…the last user header Port the line-aware strip_header() from the PHP-8.2 fix. When the stripped header was the last line of the user header bag, the previous implementation left the line break in front of it behind, and the CRLF appended after the bag then ended the header block early. With Authorization, Cookie or Proxy-Authorization now being stripped on cross-origin redirects, this could hit a body-preserving 307/308 POST: the target received a header block cut off after the preceding header and the wrong bytes as the body. The ported version also removes folded continuation lines of the stripped header and tolerates whitespace before the colon, so a header written as "Authorization : ..." cannot slip through.
* PHP-8.5: Fix GHSA-fpwc-w8rq-cr92: do not cut the request short when stripping the last user header
* PHP-8.6: Fix GHSA-fpwc-w8rq-cr92: do not cut the request short when stripping the last user header
* PHP-8.4: CI updates after forking 8.6
* PHP-8.5: CI updates after forking 8.6
* PHP-8.6: CI updates after forking 8.6
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
See Commits and Changes for more details.
Created by
pull[bot] (v2.0.0-alpha.4)
Can you help keep this open source service alive? 💖 Please sponsor : )