[php-src] Issue #22034: PDO\Sqlite::loadExtension loads arbitrary shared objects
[email protected] (thomas-chauchefoin-tob)
| Newsgroups | php.bugs |
|---|---|
| Message-ID | <OWChOPgDQxta5X4iHikQjQESXCRs31shWwkPWXnVOMk@main.internal.php.net> |
Issue: https://github.com/php/php-src/issues/22034
Author: thomas-chauchefoin-tob
### Description
Unlike `SQLite3::loadExtension`, `Pdo\Sqlite::loadExtension` does not check `sqlite3.extension_dir` and calls `sqlite3_load_extension` with the absolute path to the `extension` parameter. This allows executing native code from PHP code subject to `open_basedir` / `disable_functions` (which are not security boundaries anyway).
https://github.com/php/php-src/blob/769441ba430995733d2ad21727d51b1ace115317/ext/pdo_sqlite/pdo_sqlite.c#L102-L113
I'll open a PR with my patch later this week. It introduces a similar check to `SQLite3::loadExtension` and restricts extension loading to a trusted directory (`sqlite3.extension_dir`) set in advance.
### PHP Version
```plain
PHP 8.6.0-dev (cli) (built: May 10 2026 23:58:07) (NTS)
Copyright © The PHP Group and Contributors
Zend Engine v4.6.0-dev, Copyright © Zend by Perforce
with Zend OPcache v8.6.0-dev, Copyright ©, by Zend by Perforce
```
### Operating System
_No response_