Visitar URL original
use-after-free when an error handler removes a failing zlib.inflate filter by EdmondDantes · Pull Request #24176 · php/php-src · GitHub
Skip to content

use-after-free when an error handler removes a failing zlib.inflate filter - #24176

Open
EdmondDantes wants to merge 1 commit into
php:PHP-8.4from
true-async:zlib-inflate-error-handler
Open

EdmondDantes wants to merge 1 commit into
php:PHP-8.4from
true-async:zlib-inflate-error-handler

Conversation

@EdmondDantes

Copy link
Copy Markdown

On a corrupt input zlib.inflate raises E_NOTICE ("zlib: data error") and then resets its input pointers. A user error handler that calls stream_filter_remove() on that filter frees the filter's state first, so the reset writes to freed memory (Valgrind: invalid writes in php_zlib_inflate_filter()). The fix resets the state before raising the notice; nothing touches the filter after it.

Test: ext/zlib/tests/zlib_filter_inflate_error_handler_removes_filter.phpt, as a write and as a read filter.

Not covered, same family: an error handler that closes the stream itself during any filter's diagnostic (fclose() is only refused while a user filter runs), which would need PHP_STREAM_FLAG_NO_FCLOSE around the whole filter chain walk.

…te filter

The filter raised its notice and then reset its state; an error handler
that removed the filter had freed that state by then.
@Sjord

Sjord commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Looks good to me.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants