Skip to content

Commit

Permalink
Fix leak in SplObjectStorage unserialization
Browse files Browse the repository at this point in the history
The result of php_var_unserialize always needs to be destroyed,
even if the call failed.
  • Loading branch information
nikic committed Sep 16, 2019
1 parent 81cefab commit 8873df8
Show file tree
Hide file tree
Showing 2 changed files with 18 additions and 0 deletions.
2 changes: 2 additions & 0 deletions ext/spl/spl_observer.c
Original file line number Diff line number Diff line change
Expand Up @@ -804,12 +804,14 @@ SPL_METHOD(SplObjectStorage, unserialize)
}
/* store reference to allow cross-references between different elements */
if (!php_var_unserialize(&entry, &p, s + buf_len, &var_hash)) {
zval_ptr_dtor(&entry);
goto outexcept;
}
if (*p == ',') { /* new version has inf */
++p;
if (!php_var_unserialize(&inf, &p, s + buf_len, &var_hash)) {
zval_ptr_dtor(&entry);
zval_ptr_dtor(&inf);
goto outexcept;
}
}
Expand Down
16 changes: 16 additions & 0 deletions ext/standard/tests/serialize/unserialize_leak.phpt
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
--TEST--
Unserialize leak in SplObjectStorage
--FILE--
<?php

$payload = 'C:16:"SplObjectStorage":113:{x:i:2;O:8:"stdClass":1:{},a:2:{s:4:"prev";i:2;s:4:"next";O:8:"stdClass":0:{}};r:7;,R:2;s:4:"next";;r:3;};m:a:0:{}}';
try {
var_dump(unserialize($payload));
} catch (Exception $e) {
echo $e->getMessage(), "\n";
}

?>
--EXPECTF--
Notice: SplObjectStorage::unserialize(): Unexpected end of serialized data in %s on line %d
Error at offset 24 of 113 bytes

0 comments on commit 8873df8

Please sign in to comment.