Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Variant analysis: 1 unfixed sibling safety gap in php-src

未关闭 适合新手
#23,958 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
2/5
预计耗时
1-3 小时
新手友好度
72/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
活跃
技术栈
c, php
领域
security

调研方向

从 ext/mbstring/libmbfl/mbfilter.c 中的 mbfl_name2encoding_ex() 开始,重点查看第 335 行附近用于哈希查找的 strncasecmp 调用。将其与另外两个受保护的同级调用位置进行比较,并运行 php_php-fuzz-parser harness 或相关的 mbstring 操作,以调查报告中的路径。完成的标准是:遗漏的同级调用得到一致处理,并且报告的越界读取行为得到验证或证伪。

由索引模型根据 Issue 内容生成。

描述

Summary

Variant analysis of historical fixes in php-src identified 1 code site where an integer-overflow guard, bounds check, or safe-allocation wrapper exists at one location but is missing at a structurally identical sibling location (same file, same function, or same pattern family) elsewhere in the codebase.

Each finding below is code-confirmed against the current HEAD (verified by cloning the repository fresh and checking the pattern is still present), with the exact file/line locations, the root cause, a description of the trigger path, and — where available — ASan/execution verification output or a proof-of-concept.

Note on origin: these were surfaced by an automated variant-analysis pipeline that diffs historical fix commits against sibling code paths, then has each candidate manually reviewed. I'm posting them together per-project rather than as separate issues to respect maintainer time. Happy to split, close, or reprioritize any of these as you see fit.


Finding 1: PHP — mbfl_name2encoding_ex() hash-path OOB read (sibling of strncasecmp strlen fix)

Verified against HEAD: e64029962d0e3378a41e6948557992c7ddae503d (2026-09-25)

*- Project: PHP (php/php-src)

  • Class: Heap-buffer-overflow read (strncasecmp past buffer end via hash-path bypass of strlen guard)
  • Status: Code-confirmed, exec-blocked
  • Sibling of: CVE-2026-6104 fix — added strlen guards to 2 of 3 strncasecmp call sites in same function*

Discovery method

Variant analysis. The CVE-2026-6104 fix added strlen() guards before strncasecmp() calls in mbfl_name2encoding_ex() to prevent reading past the input string. Two of the three call sites were fixed — the third, in the hash-lookup fast path, was missed.

Vulnerable code

ext/mbstring/libmbfl/mbfl/mbfilter.c, line ~335 — mbfl_name2encoding_ex():

// VULNERABLE — hash-lookup fast path:
const mbfl_encoding *mbfl_name2encoding_ex(const char *name, size_t name_len) {
    // ... hash computation on name ...
    
    // FIXED paths (2 call sites): guard with strlen(name) before strncasecmp
    // MISSED path (1 call site, line ~335):
    if (!strncasecmp(name, enc->name, name_len)) {  // OOB read!
        // enc->name could be shorter than name_len
        // strncasecmp reads min(strlen(name), name_len, strlen(enc->name)) bytes
        // if enc->name is "\0" (1 byte) and name_len = 23, reads 1 byte past enc->name
    }
}

FIXED siblings (same function, other call sites):

// SAFE — explicit strlen guard:
if (strlen(enc_name) == name_len && !strncasecmp(name, enc_name, name_len)) {
    // strlen guard prevents OOB
}

Root cause

strncasecmp(s1, s2, n) reads up to n bytes from BOTH s1 and s2. It stops early if either string is shorter — but only AFTER comparing the shorter string's bytes. If s2 (encoding name from the table) is shorter than name_len, strncasecmp reads strlen(s2) bytes and stops. This is safe. But the hash path resolves to a name WITHOUT checking that enc->name length >= name_len. If the hash collision produces an encoding entry whose name is longer or equal, it's safe. If shorter, OOB read of whatever bytes follow enc->name in the data section.

The existing fixes added strlen(enc_name) == name_len before the strncasecmp call — a mechanical guard that the hash path lacks.

Trigger path

  1. Crafted mb_convert_encoding() or mb_detect_encoding() call with a specifically chosen encoding name
  2. → name hashes to an encoding table entry with a shorter name
  3. → strncasecmp reads past enc->name into adjacent static data → OOB read

Fuzz harness: php_php-fuzz-parser (an OSS-Fuzz/fuzzbench harness) — exercises PHP parsing including mbstring operations.

Sibling-gap quality

Excellent. Same function, same strncasecmp pattern, same strlen guard. Two call sites fixed, one missed. The fix is a one-line copy.


Analysis date: 2026-09-22. Code-confirmed, not execution-verified.


Methodology

For each historical vulnerability fix in the codebase, we identified the safe pattern the fix introduced (an overflow guard, a safe allocator wrapper, a bounds check) and searched the rest of the codebase for structurally identical code that predates or postdates the fix but never received it. Each candidate was then manually verified against the current HEAD listed above.

Happy to provide anything else that would help triage — additional PoC inputs, a minimal patch following the existing safe-sibling pattern, or a written reproduction script.

主要语言
C
星标
40.4k
派生
8.2k
平均合并
2 天 9 小时
30 天内合并 PR
122

环境准备

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

php/php-src 的其他 Issue

查看 php/php-src 的全部 Issue

相似的 Issue

更多 C Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。