Skip to content

Conversation

nielsdos
Copy link
Member

@nielsdos nielsdos commented Dec 5, 2024

The first while loop sets the bucket variable, and this is freed in out_failure. However, when the second "goto out_failure" is triggered then bucket still refers to the bucket from the first while loop, causing a UAF.
Fix this by separating the error paths.

The first while loop sets the bucket variable, and this is freed in
out_failure. However, when the second "goto out_failure" is triggered
then bucket still refers to the bucket from the first while loop,
causing a UAF.
Fix this by separating the error paths.
@nielsdos nielsdos linked an issue Dec 5, 2024 that may be closed by this pull request
@nielsdos nielsdos closed this in ddbd396 Dec 6, 2024
charmitro pushed a commit to wasix-org/php that referenced this pull request Mar 13, 2025
The first while loop sets the bucket variable, and this is freed in
out_failure. However, when the second "goto out_failure" is triggered
then bucket still refers to the bucket from the first while loop,
causing a UAF.
Fix this by separating the error paths.

Closes phpGH-17058.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

UAF on iconv filter failure

3 participants