Variant analysis: 1 unfixed sibling safety gap in php-src
Mantenedores costumam responder em até 1 dia
@kamil-tekiela já está trabalhando nisso.
Desde 29/9/2026.
Avaliação
- Dificuldade
- 2/5
- Tempo estimado
- 1-3 horas
- Facilidade para iniciantes
- 72/100
Direção de pesquisa
Comece em ext/mbstring/libmbfl/mbfilter.c, em mbfl_name2encoding_ex(), especialmente na chamada a strncasecmp de busca no hash próxima à linha 335. Compare-a com os dois locais de chamada irmãos protegidos e execute o harness php_php-fuzz-parser ou operações relevantes de mbstring para investigar o caminho relatado. O trabalho estará concluído quando o irmão não tratado for abordado de forma consistente e o comportamento relatado de leitura fora dos limites for verificado ou refutado.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Summary
Variant analysis of historical fixes in php-src identified 1 code site where an integer-overflow guard, bounds check, or safe-allocation wrapper exists at one location but is missing at a structurally identical sibling location (same file, same function, or same pattern family) elsewhere in the codebase.
Each finding below is code-confirmed against the current HEAD (verified by cloning the repository fresh and checking the pattern is still present), with the exact file/line locations, the root cause, a description of the trigger path, and — where available — ASan/execution verification output or a proof-of-concept.
Note on origin: these were surfaced by an automated variant-analysis pipeline that diffs historical fix commits against sibling code paths, then has each candidate manually reviewed. I'm posting them together per-project rather than as separate issues to respect maintainer time. Happy to split, close, or reprioritize any of these as you see fit.
Finding 1: PHP — mbfl_name2encoding_ex() hash-path OOB read (sibling of strncasecmp strlen fix)
Verified against HEAD: e64029962d0e3378a41e6948557992c7ddae503d (2026-09-25)
*- Project: PHP (php/php-src)
- Class: Heap-buffer-overflow read (strncasecmp past buffer end via hash-path bypass of strlen guard)
- Status: Code-confirmed, exec-blocked
- Sibling of: CVE-2026-6104 fix — added strlen guards to 2 of 3
strncasecmpcall sites in same function*
Discovery method
Variant analysis. The CVE-2026-6104 fix added strlen() guards before strncasecmp() calls in mbfl_name2encoding_ex() to prevent reading past the input string. Two of the three call sites were fixed — the third, in the hash-lookup fast path, was missed.
Vulnerable code
ext/mbstring/libmbfl/mbfl/mbfilter.c, line ~335 — mbfl_name2encoding_ex():
// VULNERABLE — hash-lookup fast path:
const mbfl_encoding *mbfl_name2encoding_ex(const char *name, size_t name_len) {
// ... hash computation on name ...
// FIXED paths (2 call sites): guard with strlen(name) before strncasecmp
// MISSED path (1 call site, line ~335):
if (!strncasecmp(name, enc->name, name_len)) { // OOB read!
// enc->name could be shorter than name_len
// strncasecmp reads min(strlen(name), name_len, strlen(enc->name)) bytes
// if enc->name is "\0" (1 byte) and name_len = 23, reads 1 byte past enc->name
}
}
FIXED siblings (same function, other call sites):
// SAFE — explicit strlen guard:
if (strlen(enc_name) == name_len && !strncasecmp(name, enc_name, name_len)) {
// strlen guard prevents OOB
}
Root cause
strncasecmp(s1, s2, n) reads up to n bytes from BOTH s1 and s2. It stops early if either string is shorter — but only AFTER comparing the shorter string's bytes. If s2 (encoding name from the table) is shorter than name_len, strncasecmp reads strlen(s2) bytes and stops. This is safe. But the hash path resolves to a name WITHOUT checking that enc->name length >= name_len. If the hash collision produces an encoding entry whose name is longer or equal, it's safe. If shorter, OOB read of whatever bytes follow enc->name in the data section.
The existing fixes added strlen(enc_name) == name_len before the strncasecmp call — a mechanical guard that the hash path lacks.
Trigger path
- Crafted
mb_convert_encoding()ormb_detect_encoding()call with a specifically chosen encoding name - → name hashes to an encoding table entry with a shorter name
- →
strncasecmpreads pastenc->nameinto adjacent static data → OOB read
Fuzz harness: php_php-fuzz-parser (an OSS-Fuzz/fuzzbench harness) — exercises PHP parsing including mbstring operations.
Sibling-gap quality
Excellent. Same function, same strncasecmp pattern, same strlen guard. Two call sites fixed, one missed. The fix is a one-line copy.
Analysis date: 2026-09-22. Code-confirmed, not execution-verified.
Methodology
For each historical vulnerability fix in the codebase, we identified the safe pattern the fix introduced (an overflow guard, a safe allocator wrapper, a bounds check) and searched the rest of the codebase for structurally identical code that predates or postdates the fix but never received it. Each candidate was then manually verified against the current HEAD listed above.
Happy to provide anything else that would help triage — additional PoC inputs, a minimal patch following the existing safe-sibling pattern, or a written reproduction script.
- Linguagem predominante
- C
- Estrelas
- 40.4k
- Forks
- 8.2k
- Merge médio
- 2d 3h
- PRs com merge (30d)
- 151
Preparar o ambiente
- Sem Dockerfile nem arquivo Docker Compose
- Sem modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de php/php-src
-
NULL pointer dereference in php_ini.c (PHP 8.3)Talvez já em andamento Um pull request vinculado a esta issue está aberto ou já foi mesclado. AbertaBug Status: Needs Triage
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 82/100
Mantenedores costumam responder em até 1 dia
-
Bug Status: Needs Feedback
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 74/100
php/php-src#24121 · 2 comentários ·
Mantenedores costumam responder em até 1 dia
-
sapi_lsapi_ub_write does not return bytes written in lsapi modeTalvez já em andamento Um pull request vinculado a esta issue está aberto ou já foi mesclado. AbertaBug Status: Needs Triage
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 90/100
Mantenedores costumam responder em até 1 dia
-
Bug Status: Needs Triage
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
Mantenedores costumam responder em até 1 dia
-
Flaky hrtime.phpt testTalvez já em andamento @veksa assumiu há 62 dias. AbertaBug Category: Tests Status: Verified
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
Mantenedores costumam responder em até 1 dia
Todas as issues de php/php-src
Issues semelhantes
-
bug
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 74/100
EchoTools/nevr-runtime#117 · 2 comentários ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 67/100
DarkFlippers/qUnleashed#240 ·
Mantenedores costumam responder em até 1 dia
-
enhancement
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
HarbourMasters/Shipwright#7320 ·
Mantenedores costumam responder em até 1 dia
-
area/documentation status/awaiting-triage
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 76/100
yugabyte/yugabyte-db#34660 ·
Mantenedores costumam responder em até 1 dia