{"schema_version":"1.7.2","id":"OESA-2026-3009","modified":"2026-07-19T03:47:40Z","published":"2026-07-19T03:47:40Z","upstream":["CVE-2026-54789"],"summary":"mod_auth_openidc security update","details":"This module enables an Apache 2.x web server to operate as an OpenID Connect Relying Party(RP) to an OpenID Connect Provider(OP).\r\n\r\nSecurity Fix(es):\n\nAn out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`. `oidc_state_cookies_parse_token()` (`src/state.c`) scans a cookie token for the `=` that separates the cookie name from its value with a loop whose only real termination condition is finding a `=` byte — it does not stop at the string terminator. The `cookie != NULL` test can never become false, because `cookie` is only ever incremented (never reassigned to `NULL`). A request whose `Cookie` header contains a token that begins with the configured state-cookie prefix (default `mod_auth_openidc_state_`) but contains no `=` makes the loop walk past the end of the token buffer, reading adjacent process memory until it happens to encounter a `=` (`0x3D`) byte, and then writing a `NUL` byte at that out-of-bounds location. This parser runs early on requests that begin a new authentication flow and on requests to the `OIDCRedirectURI` callback — before any session or state validation — so the condition is reachable by an unauthenticated, remote client that fully controls the `Cookie` header.(CVE-2026-54789)","affected":[{"package":{"ecosystem":"openEuler:22.03-LTS-SP4","name":"mod_auth_openidc","purl":"pkg:rpm/openEuler/mod_auth_openidc&distro=openEuler-22.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.19.4-1.oe2203sp4"}]}],"ecosystem_specific":{"aarch64":["mod_auth_openidc-2.4.19.4-1.oe2203sp4.aarch64.rpm","mod_auth_openidc-debuginfo-2.4.19.4-1.oe2203sp4.aarch64.rpm","mod_auth_openidc-debugsource-2.4.19.4-1.oe2203sp4.aarch64.rpm"],"src":["mod_auth_openidc-2.4.19.4-1.oe2203sp4.src.rpm"],"x86_64":["mod_auth_openidc-2.4.19.4-1.oe2203sp4.x86_64.rpm","mod_auth_openidc-debuginfo-2.4.19.4-1.oe2203sp4.x86_64.rpm","mod_auth_openidc-debugsource-2.4.19.4-1.oe2203sp4.x86_64.rpm"]}}],"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3009"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54789"}],"database_specific":{"severity":"High"}}
