Skip to content

Commit fac360c

Browse files
committed
Merge branch 'PHP-8.5' into PHP-8.6
* PHP-8.5: Fix GH-23352: DOMDocument::adoptNode() stale document references
2 parents d410a46 + dd83055 commit fac360c

4 files changed

Lines changed: 67 additions & 0 deletions

File tree

‎ext/dom/document.c‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1085,6 +1085,9 @@ static void php_dom_transfer_document_ref_single_aux(xmlNodePtr node, php_libxml
10851085
if (node->type == XML_ELEMENT_NODE) {
10861086
for (xmlAttrPtr attr = node->properties; attr != NULL; attr = attr->next) {
10871087
php_dom_transfer_document_ref_single_node((xmlNodePtr) attr, new_document);
1088+
for (xmlNodePtr child = attr->children; child; child = child->next) {
1089+
php_dom_transfer_document_ref_single_node((xmlNodePtr) child, new_document);
1090+
}
10881091
}
10891092
}
10901093
}
Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
--TEST--
2+
DOMDocument::adoptNode() with a node retained under a later sibling
3+
--EXTENSIONS--
4+
dom
5+
--FILE--
6+
<?php
7+
8+
$source = new DOMDocument();
9+
$root = $source->appendChild($source->createElement('root'));
10+
$root->appendChild($source->createElement('first'));
11+
$second = $root->appendChild($source->createElement('second'));
12+
$victim = $second->appendChild($source->createElement('grandchild'));
13+
14+
$destination = new DOMDocument();
15+
$destination->appendChild($destination->adoptNode($root));
16+
unset($destination, $source, $root, $second);
17+
18+
echo $victim->nodeName, PHP_EOL;
19+
20+
?>
21+
--EXPECT--
22+
grandchild

‎ext/dom/tests/gh23352.phpt‎

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
--TEST--
2+
GH-23352 (UAF reading an attribute value node retained across DOMDocument::adoptNode())
3+
--EXTENSIONS--
4+
dom
5+
--FILE--
6+
<?php
7+
8+
$source = new DOMDocument();
9+
$element = $source->appendChild($source->createElement('element'));
10+
$element->setAttribute('attribute', 'victim');
11+
$victim = $element->getAttributeNode('attribute')->firstChild;
12+
13+
$destination = new DOMDocument();
14+
$destination->appendChild($destination->adoptNode($element));
15+
unset($destination, $source, $element);
16+
17+
echo $victim->data, PHP_EOL;
18+
19+
?>
20+
--EXPECT--
21+
victim
Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
--TEST--
2+
GH-23352 (UAF reading an attribute value node retained across Dom\Document::adoptNode())
3+
--EXTENSIONS--
4+
dom
5+
--FILE--
6+
<?php
7+
8+
$source = Dom\XMLDocument::createFromString('<root/>');
9+
$element = $source->documentElement;
10+
$element->setAttribute('attribute', 'victim');
11+
$victim = $element->getAttributeNode('attribute')->firstChild;
12+
13+
$destination = Dom\XMLDocument::createEmpty();
14+
$destination->appendChild($destination->adoptNode($element));
15+
unset($destination, $source, $element);
16+
17+
echo $victim->data, PHP_EOL;
18+
19+
?>
20+
--EXPECT--
21+
victim

0 commit comments

Comments
 (0)