[php-src] master: Merge branch 'PHP-8.5'
David Carlier <[email protected]>
| Newsgroups | gmane.comp.php.cvs.general |
|---|---|
| Message-ID | <[email protected]> |
Author: David Carlier (devnexen)
Date: 2026-07-06T10:33:54+01:00
Commit: https://github.com/php/php-src/commit/750074beb5c564fd2b26bbdb9c3bc63b9f7bc848
Raw diff: https://github.com/php/php-src/commit/750074beb5c564fd2b26bbdb9c3bc63b9f7bc848.diff
Merge branch 'PHP-8.5'
* PHP-8.5:
ext/standard: getimagesize()/getimagesizefromstring() overflow.
Changed paths:
A ext/standard/tests/image/getimagesizefromstring_iff_overflow.phpt
M ext/standard/image.c
Diff:
diff --git a/ext/standard/image.c b/ext/standard/image.c
index 869371842006..7ce6767126bf 100644
--- a/ext/standard/image.c
+++ b/ext/standard/image.c
@@ -876,6 +876,9 @@ static struct php_gfxinfo *php_handle_iff(php_stream * stream)
return NULL;
}
if ((size & 1) == 1) {
+ if (size == INT_MAX) {
+ return NULL;
+ }
size++;
}
if (chunkId == 0x424d4844) { /* BMHD chunk */
diff --git a/ext/standard/tests/image/getimagesizefromstring_iff_overflow.phpt b/ext/standard/tests/image/getimagesizefromstring_iff_overflow.phpt
new file mode 100644
index 000000000000..f6fdea9d8e6b
--- /dev/null
+++ b/ext/standard/tests/image/getimagesizefromstring_iff_overflow.phpt
@@ -0,0 +1,24 @@
+--TEST--
+getimagesizefromstring() IFF chunk size integer overflow (GH-getimagesize_oflow)
+--CREDITS--
+Alexandre Daubois
+--FILE--
+<?php
+// IFF/ILBM with a chunk size of INT_MAX (0x7fffffff), an odd value.
+// The parser rounds odd chunk sizes up to even via size++, which overflowed
+// when size == INT_MAX. It must be handled gracefully rather than triggering UB.
+$payload = "FORM" . "\x00\x00\x00\x00" . "ILBM" . "ABCD" . "\x7f\xff\xff\xff";
+var_dump(getimagesizefromstring($payload));
+
+// getimagesize() shares the same IFF parser through the file path.
+$file = __DIR__ . "/getimagesizefromstring_iff_overflow.iff";
+file_put_contents($file, $payload);
+var_dump(getimagesize($file));
+?>
+--CLEAN--
+<?php
+@unlink(__DIR__ . "/getimagesizefromstring_iff_overflow.iff");
+?>
+--EXPECT--
+bool(false)
+bool(false)