[php-src] Issue #22034: PDO\Sqlite::loadExtension loads arbitrary shared objects

[email protected] (thomas-chauchefoin-tob)
Newsgroups php.bugs
Message-ID <OWChOPgDQxta5X4iHikQjQESXCRs31shWwkPWXnVOMk@main.internal.php.net>
Issue: https://github.com/php/php-src/issues/22034
Author: thomas-chauchefoin-tob

### Description

Unlike `SQLite3::loadExtension`, `Pdo\Sqlite::loadExtension` does not check `sqlite3.extension_dir` and calls `sqlite3_load_extension` with the absolute path to the `extension` parameter. This allows executing native code from PHP code subject to `open_basedir` / `disable_functions` (which are not security boundaries anyway).

https://github.com/php/php-src/blob/769441ba430995733d2ad21727d51b1ace115317/ext/pdo_sqlite/pdo_sqlite.c#L102-L113

I'll open a PR with my patch later this week. It introduces a similar check to `SQLite3::loadExtension` and restricts extension loading to a trusted directory (`sqlite3.extension_dir`) set in advance.

### PHP Version

```plain
PHP 8.6.0-dev (cli) (built: May 10 2026 23:58:07) (NTS)
Copyright © The PHP Group and Contributors
Zend Engine v4.6.0-dev, Copyright © Zend by Perforce
    with Zend OPcache v8.6.0-dev, Copyright ©, by Zend by Perforce
```

### Operating System

_No response_
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.