NULL pointer dereference in php_ini.c (PHP 8.3)
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 82/100
Research direction
Read main/php_ini.c around the expand_filepath() call at line 565 and the later strlen(filename) call around line 610. Check the existing PHP INI tests before running the relevant test suite. Done means the failure path cannot dereference a NULL filename, and the behavior is covered by an appropriate test.
Written by the indexing model from the issue text.
Description
Description
At main/php_ini.c:565 the return value of expand_filepath() is assigned to pointer filename without checking whether the function returned NULL:
https://github.com/php/php-src/blob/PHP-8.3/main/php_ini.c#L563-L566
The expand_filepath() function may return NULL if path expansion fails. However, later pointer filename is dereferenced by calling strlen(filename) without an additional NULL check:
https://github.com/php/php-src/blob/PHP-8.3/main/php_ini.c#L599-L609
In the analyzed PHP 8.3 source this operation corresponds to php_ini.c:610.
This may lead to a NULL pointer dereference if expand_filepath() fails.
Possible solution
Checking the return value of expand_filepath() before using filename may prevent unexpected behavior:
filename = expand_filepath(php_ini_file_name, NULL);
if (filename) {
free_filename = true;
} else {
filename = php_ini_file_name;
}
Found by Linux Verification Center (https://portal.linuxtesting.ru/) using SVACE.
Author E. Tretiakov.
PHP Version
8.3.24 (found with static analysis)
Operating System
N/A
- Dominant language
- C
- Stars
- 40.4k
- Forks
- 8.2k
- Avg merge
- 2d 3h
- Merged PRs (30d)
- 151
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from php/php-src
-
Bug Status: Needs Feedback
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
php/php-src#24121 · 2 comments ·
Maintainers usually reply within 1 day
-
Variant analysis: 1 unfixed sibling safety gap in php-srcPossibly taken @kamil-tekiela claimed this 7 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
php/php-src#23958 · 1 assignee ·
Maintainers usually reply within 1 day
-
sapi_lsapi_ub_write does not return bytes written in lsapi modePossibly taken A pull request linked to this issue is open or already merged. OpenBug Status: Needs Triage
Difficulty 1/5 Under an hour Newbie friendliness 90/100
Maintainers usually reply within 1 day
-
Bug Status: Needs Triage
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
Flaky hrtime.phpt testPossibly taken @veksa claimed this 62 days ago. OpenBug Category: Tests Status: Verified
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day
Similar issues
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
HarbourMasters/Shipwright#7320 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
FujiNetWIFI/fujinet-firmware#1834 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
yanet-platform/yanet2#2874 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
intel/intel-lpmd#137 ·
Maintainers usually reply within 1 day