Skip to content

Fix stale read buffer length in stream filter flush - #24136

Open
bukka wants to merge 1 commit into
php:PHP-8.4from
bukka:fix-stream-filter-flush-readbuflen
Open

bukka wants to merge 1 commit into
php:PHP-8.4from
bukka:fix-stream-filter-flush-readbuflen

Conversation

@bukka

@bukka bukka commented Oct 5, 2026

Copy link
Copy Markdown
Member

When a read filter is flushed (e.g. via stream_filter_remove()) and the flushed data exceeds the remaining read buffer capacity, _php_stream_filter_flush() reallocates stream->readbuf but leaves stream->readbuflen at its old value. Once writepos exceeds the stale readbuflen, the next refill in _php_stream_fill_read_buffer() computes readbuflen - writepos as a wrapped size_t and passes it to the read op, causing EFAULT on plain files and out-of-bounds writes on memory streams.

Keep readbuflen in sync with the reallocation, as streams.c does.

When a read filter is flushed (e.g. via stream_filter_remove()) and the
flushed data exceeds the remaining read buffer capacity,
_php_stream_filter_flush() reallocates stream->readbuf but leaves
stream->readbuflen at its old value. Once writepos exceeds the stale
readbuflen, the next refill in _php_stream_fill_read_buffer() computes
readbuflen - writepos as a wrapped size_t and passes it to the read op,
causing EFAULT on plain files and out-of-bounds writes on memory streams.

Keep readbuflen in sync with the reallocation, as streams.c does.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant