Skip to content

Commit 8537aa6

Browse files
committed
Fix GH-16267 socket_strerror overflow on argument value.
only socket_strerror provides user-supplied value to sockets_strerror handler. close GH-16270
1 parent e3015de commit 8537aa6

File tree

3 files changed

+31
-0
lines changed

3 files changed

+31
-0
lines changed

NEWS

+4
Original file line numberDiff line numberDiff line change
@@ -72,6 +72,10 @@ PHP NEWS
7272
. Fixed bug GH-15837 (Segmentation fault in ext/simplexml/simplexml.c).
7373
(nielsdos)
7474

75+
- Sockets:
76+
. Fixed bug GH-16267 (socket_strerror overflow on errno argument).
77+
(David Carlier)
78+
7579
- SOAP:
7680
. Fixed bug #62900 (Wrong namespace on xsd import error message). (nielsdos)
7781
. Fixed bug GH-16237 (Segmentation fault when cloning SoapServer). (nielsdos)

ext/sockets/sockets.c

+5
Original file line numberDiff line numberDiff line change
@@ -1211,6 +1211,11 @@ PHP_FUNCTION(socket_strerror)
12111211
RETURN_THROWS();
12121212
}
12131213

1214+
if (ZEND_LONG_EXCEEDS_INT(arg1)) {
1215+
zend_argument_value_error(1, "must be between %d and %d", INT_MIN, INT_MAX);
1216+
RETURN_THROWS();
1217+
}
1218+
12141219
RETURN_STRING(sockets_strerror(arg1));
12151220
}
12161221
/* }}} */

ext/sockets/tests/gh16267.phpt

+22
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
--TEST--
2+
GH-16267 - overflow on socket_strerror argument
3+
--EXTENSIONS--
4+
sockets
5+
--SKIPIF--
6+
<?php if (PHP_INT_SIZE != 8) die('skip 64-bit only'); ?>
7+
--FILE--
8+
<?php
9+
try {
10+
socket_strerror(PHP_INT_MIN);
11+
} catch (\ValueError $e) {
12+
echo $e->getMessage() . PHP_EOL;
13+
}
14+
try {
15+
socket_strerror(PHP_INT_MAX);
16+
} catch (\ValueError $e) {
17+
echo $e->getMessage() . PHP_EOL;
18+
}
19+
?>
20+
--EXPECTF--
21+
socket_strerror(): Argument #1 ($error_code) must be between %s and %s
22+
socket_strerror(): Argument #1 ($error_code) must be between %s and %s

0 commit comments

Comments
 (0)