Skip to content

use-after-free when an error handler removes a failing zlib.inflate filter - #24176

Closed
EdmondDantes wants to merge 1 commit into
php:PHP-8.4from
true-async:zlib-inflate-error-handler
Closed

EdmondDantes wants to merge 1 commit into
php:PHP-8.4from
true-async:zlib-inflate-error-handler

Conversation

@EdmondDantes

Copy link
Copy Markdown
Contributor

On a corrupt input zlib.inflate raises E_NOTICE ("zlib: data error") and then resets its input pointers. A user error handler that calls stream_filter_remove() on that filter frees the filter's state first, so the reset writes to freed memory (Valgrind: invalid writes in php_zlib_inflate_filter()). The fix resets the state before raising the notice; nothing touches the filter after it.

Test: ext/zlib/tests/zlib_filter_inflate_error_handler_removes_filter.phpt, as a write and as a read filter.

Not covered, same family: an error handler that closes the stream itself during any filter's diagnostic (fclose() is only refused while a user filter runs), which would need PHP_STREAM_FLAG_NO_FCLOSE around the whole filter chain walk.

…te filter

The filter raised its notice and then reset its state; an error handler
that removed the filter had freed that state by then.
@Sjord

Sjord commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Looks good to me.

@LamentXU123 LamentXU123 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

LamentXU123 added a commit that referenced this pull request Oct 9, 2026
* PHP-8.6:
  Fix use-after-free when removing a failing zlib.inflate filter (#24176)
wheakerd pushed a commit to wheakerd/php-src that referenced this pull request Oct 9, 2026
* PHP-8.4:
  Fix use-after-free when removing a failing zlib.inflate filter (php#24176)
wheakerd pushed a commit to wheakerd/php-src that referenced this pull request Oct 9, 2026
* PHP-8.5:
  Fix use-after-free when removing a failing zlib.inflate filter (php#24176)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants