NULL pointer dereference in php_ini.c (PHP 8.3)
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
调研方向
阅读main/php_ini.c中第 565 行expand_filepath()调用附近的代码,以及约第 610 行后续的strlen(filename)调用附近的代码。运行相关测试套件之前,先检查现有的 PHP INI 测试。完成标准是:失败路径无法对 NULL 的filename进行解引用,并且有适当的测试覆盖该行为。
由索引模型根据 Issue 内容生成。
描述
Description
At main/php_ini.c:565 the return value of expand_filepath() is assigned to pointer filename without checking whether the function returned NULL:
https://github.com/php/php-src/blob/PHP-8.3/main/php_ini.c#L563-L566
The expand_filepath() function may return NULL if path expansion fails. However, later pointer filename is dereferenced by calling strlen(filename) without an additional NULL check:
https://github.com/php/php-src/blob/PHP-8.3/main/php_ini.c#L599-L609
In the analyzed PHP 8.3 source this operation corresponds to php_ini.c:610.
This may lead to a NULL pointer dereference if expand_filepath() fails.
Possible solution
Checking the return value of expand_filepath() before using filename may prevent unexpected behavior:
filename = expand_filepath(php_ini_file_name, NULL);
if (filename) {
free_filename = true;
} else {
filename = php_ini_file_name;
}
Found by Linux Verification Center (https://portal.linuxtesting.ru/) using SVACE.
Author E. Tretiakov.
PHP Version
8.3.24 (found with static analysis)
Operating System
N/A
- 主要语言
- C
- 星标
- 40.4k
- 派生
- 8.2k
- 平均合并
- 1 天 23 小时
- 30 天内合并 PR
- 150
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
php/php-src 的其他 Issue
-
Bug Status: Needs Triage
难度 2/5 1-3 小时 新手友好度 62/100
维护者通常 1 天内回复
-
Feature Status: Needs Triage
难度 2/5 1-3 小时 新手友好度 73/100
维护者通常 1 天内回复
-
Sockets from synchronous stream_socket_client() are left in non-blocking mode on Windows可能已有人在做 关联的 PR 仍在进行中或已合并。 未关闭Bug Status: Needs Triage
难度 2/5 1-3 小时 新手友好度 66/100
维护者通常 1 天内回复
-
Variant analysis: 1 unfixed sibling safety gap in php-src可能已有人在做 @kamil-tekiela 于 10 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复
-
sapi_lsapi_ub_write does not return bytes written in lsapi mode可能已有人在做 关联的 PR 仍在进行中或已合并。 未关闭Bug Status: Needs Triage
难度 1/5 1 小时以内 新手友好度 90/100
维护者通常 1 天内回复
相似的 Issue
-
enhancement good first issue
难度 2/5 1-3 小时 新手友好度 66/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
NASA-AMMOS/BSL#355 ·
维护者通常 1 天内回复
-
bug
难度 2/5 1-3 小时 新手友好度 78/100
arancormonk/dsd-neo#660 ·
维护者通常 1 天内回复
-
[Bug]: remote-ls --updates reports up-to-date OCI refs because it ignores deployed Alt-id可能已有人在做 @Joao-kouznetz 今天认领。 未关闭
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复