execution or denial of service via use-after-free in mod_ldap per-directory configuration (CVE-2026-29167)
47 lines
1.9 KiB
Diff
47 lines
1.9 KiB
Diff
From 88568e901f41fdd527d180970f7f372f88b93260 Mon Sep 17 00:00:00 2001
|
|
From: Joe Orton <jorton@apache.org>
|
|
Date: Wed, 3 Jun 2026 17:09:40 +0000
|
|
Subject: [PATCH] Merge r1934932 from trunk:
|
|
|
|
* modules/ldap/util_ldap.c (uldap_connection_find): Fix inheritance in
|
|
per-dir context.
|
|
|
|
Reviewed by: jorton, covener, jfclere
|
|
|
|
|
|
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.4.x@1934935 13f79535-47bb-0310-9956-ffa450edef68
|
|
---
|
|
modules/ldap/util_ldap.c | 19 +++++++++++++++++--
|
|
1 file changed, 17 insertions(+), 2 deletions(-)
|
|
|
|
diff --git a/modules/ldap/util_ldap.c b/modules/ldap/util_ldap.c
|
|
index 8c9e58717d..0f13d912c3 100644
|
|
--- a/modules/ldap/util_ldap.c
|
|
+++ b/modules/ldap/util_ldap.c
|
|
@@ -897,8 +897,23 @@ static util_ldap_connection_t *
|
|
*/
|
|
l->secure = secureflag;
|
|
|
|
- /* save away a copy of the client cert list that is presently valid */
|
|
- l->client_certs = apr_array_copy_hdr(l->pool, dc->client_certs);
|
|
+ /* Deep-copy the client cert list into the connection pool so that
|
|
+ * the cached connection does not retain pointers into the
|
|
+ * (potentially short-lived) per-directory config pool.
|
|
+ */
|
|
+ l->client_certs = apr_array_copy(l->pool, dc->client_certs);
|
|
+ if (!apr_is_empty_array(l->client_certs)) {
|
|
+ int i;
|
|
+ apr_ldap_opt_tls_cert_t *certs;
|
|
+
|
|
+ certs = (apr_ldap_opt_tls_cert_t *)l->client_certs->elts;
|
|
+ for (i = 0; i < l->client_certs->nelts; i++) {
|
|
+ if (certs[i].path)
|
|
+ certs[i].path = apr_pstrdup(l->pool, certs[i].path);
|
|
+ if (certs[i].password)
|
|
+ certs[i].password = apr_pstrdup(l->pool, certs[i].password);
|
|
+ }
|
|
+ }
|
|
|
|
/* whether or not to keep this connection in the pool when it's returned */
|
|
l->keep = (st->connection_pool_ttl == 0) ? 0 : 1;
|