Skip to content

ext/session: check the created ID before validating it - #22924

Open
iliaal wants to merge 1 commit into
php:PHP-8.4from
iliaal:fix/session-create-id-null-sid
Open

ext/session: check the created ID before validating it#22924
iliaal wants to merge 1 commit into
php:PHP-8.4from
iliaal:fix/session-create-id-null-sid

Conversation

@iliaal

@iliaal iliaal commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

session_create_id() hands the return value of s_create_sid() straight to s_validate_sid(). A userland create_sid() that throws makes ps_create_sid_user() return NULL, and ps_validate_sid_user() then reaches ZVAL_STR_COPY() with a NULL key.

Reproducer is a SessionHandler subclass whose create_sid() throws on its second call, with validateId() defined, then session_create_id() on an active session: SIGSEGV on 8.4, 8.5 and master. The four other s_create_sid() call sites, in php_session_initialize() and session_regenerate_id(), already test for NULL; #22580 covers the remaining one in SessionHandler::create_sid().

session_create_id() passes the return value of s_create_sid() straight
into s_validate_sid(). A userland create_sid() that throws makes
ps_create_sid_user() return NULL, and ps_validate_sid_user() then reaches
ZVAL_STR_COPY() with a NULL key. Stop the retry loop when no ID was
created and propagate a pending exception instead of reporting a plain
failure. The four s_create_sid() call sites in php_session_initialize()
and session_regenerate_id() already test for NULL.

Closes phpGH-22924
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant