Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9f67-6fw4-hpfp

Опубликовано: 24 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9

Описание

PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can cause DoS

Summary

On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, CONIN$ and CONOUT$ when they appear as a component of a path. An attacker-controlled filename therefore reaches CreateFileW() and opens a device instead of the regular file the application expected, which can block or hang the request and exhaust worker processes.

Details

Paths from application code flow through the stream wrapper layer into the Windows I/O layer. file_get_contents() opens the requested path via php_stream_open_wrapper_ex(), and move_uploaded_file() reaches VCWD_RENAME() and php_copy_file_ex(), so paths built from user-controlled upload filenames arrive at the same place.

The Windows path validation macro checks only for trailing spaces and certain trailing dots:

https://github.com/php/php-src/blob/php-8.5.10/win32/ioutil.h#L156-L169

There is no check for reserved device names, and php_win32_ioutil_open_w() passes the path straight to CreateFileW():

https://github.com/php/php-src/blob/php-8.5.10/win32/ioutil.c#L205

That device handles can result from ordinary file opening is visible further on, where a handle whose GetFileType() is FILE_TYPE_CHAR is marked as S_IFCHR in win32/ioutil.c and simply flagged as non-seekable in main/streams/plain_wrapper.c, rather than being rejected.

The fix adds php_win32_ioutil_path_kind_w() and php_win32_ioutil_path_kind_a(), which classify a path as ordinary, a bare device name, or a path containing a reserved component. Reserved components are rejected with ERROR_INVALID_NAME before any I/O, while bare device names such as NUL and NUL: keep working for backwards compatibility, and DOS device paths (\\.\, \\?\ and \??\) are left alone because Windows does not map device names inside them. Variants such as NUL.txt, aux:stream and NUL are resolved through RtlIsDosDeviceName_U so that PHP follows the behaviour of the Windows version it runs on.

PoC

<?php $base = 'C:\\temp\\php-poc'; $file = $_GET['file'] ?? 'test.txt'; $path = $base . DIRECTORY_SEPARATOR . $file; echo "path = " . $path . PHP_EOL; echo file_get_contents($path);

Requesting the script with ?file=CON, ?file=CONIN$ or ?file=NUL.txt makes PHP open the corresponding device rather than failing on a missing file. CONIN$ blocks waiting for console input, which holds the request open.

The regression test is ext/standard/tests/file/ghsa-9f67-6fw4-hpfp-win32.phpt.

Impact

A PHP application on Windows that builds a path from user input, such as a download endpoint or an upload destination taken from the client-supplied filename, can be made to operate on a device instead of a file. Depending on the device and the operation this blocks or hangs the request, produces unexpected read and write behaviour, or returns errors from the native API. Under concurrency, repeated requests to a blocking device exhaust the worker pool and deny service.

Only Windows deployments are affected. Reserved names are a Windows filesystem concept, and paths like CON.txt are devices there rather than ordinary filenames, which is why application-level path joining and normalisation does not catch them. The same class of issue has required fixes in other language ecosystems.

Пакеты

Наименование

php

php
Затронутые версииВерсия исправления

>=8.2.0, <8.2.34

8.2.34

Наименование

php

php
Затронутые версииВерсия исправления

>=8.3.0, <8.3.35

8.3.35

Наименование

php

php
Затронутые версииВерсия исправления

>=8.4.0, <8.4.26

8.4.26

Наименование

php

php
Затронутые версииВерсия исправления

>=8.5.0, <8.5.11

8.5.11

EPSS

Процентиль: 23%
0.00322
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-67

Связанные уязвимости

ubuntu
8 дней назад

On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, CONIN$ and CONOUT$ when they appear as a component of a path. An attacker-controlled filename therefore reaches CreateFileW() and opens a device instead of the regular file the application expected, which can block or hang the request and exhaust worker processes.

CVSS3: 5.9
redhat
8 дней назад

On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, CONIN$ and CONOUT$ when they appear as a component of a path. An attacker-controlled filename therefore reaches CreateFileW() and opens a device instead of the regular file the application expected, which can block or hang the request and exhaust worker processes.

nvd
8 дней назад

On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, CONIN$ and CONOUT$ when they appear as a component of a path. An attacker-controlled filename therefore reaches CreateFileW() and opens a device instead of the regular file the application expected, which can block or hang the request and exhaust worker processes.

msrc
2 дня назад

PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can cause DoS

debian
8 дней назад

On Windows, PHP's filesystem and stream APIs do not reject reserved de ...

EPSS

Процентиль: 23%
0.00322
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-67