Описание
ext/filter: encode 0xFF in FILTER_SANITIZE_ENCODED
Summary
php_filter_encode_url() builds a 256-entry lookup table that decides which bytes FILTER_SANITIZE_ENCODED percent-encodes, but initialises only the first 255 entries. Entry 255 is read uninitialised, so whether the byte 0xFF is encoded or passed through depends on whatever happened to be on the stack.
Details
The table is filled with memset(tmp, 1, sizeof(tmp) - 1), which leaves tmp[255] untouched:
https://github.com/php/php-src/blob/php-8.5.9/ext/filter/sanitizing_filters.c#L73
The filter then consults tmp[*s] for every input byte, so for 0xFF the decision comes from uninitialised stack memory. Every other byte is handled deterministically.
The fix changes the memset() length to sizeof(tmp) so the whole table is initialised.
PoC
0xFE is percent-encoded as %FE while 0xFF is passed through raw, showing that tmp[255] was read uninitialised.
Impact
The impact is low. There is no crash and no memory corruption; the only effect is that the 0xFF byte is sanitised inconsistently, depending on uninitialised stack contents. A downstream consumer that relies on FILTER_SANITIZE_ENCODED producing fully percent-encoded output could in principle be affected as part of a longer chain, but the filter provides no such guarantee on its own.
This issue was fixed publicly in 8.4.25 and 8.5.10 before it was recognised as security relevant, and is backported here to the branches that receive security fixes only.
Пакеты
php
>=8.2.0, <8.2.34
8.2.34
php
>=8.3.0, <8.3.35
8.3.35
php
>=8.4.0, <8.4.25
8.4.25
php
>=8.5.0, <8.5.10
8.5.10
3.7 Low
CVSS3
3.7 Low
CVSS3