Skip to content

mod_speling: avoid out-of-bounds read in check_speling - #778

Open
arshsmith1 wants to merge 1 commit into
apache:trunkfrom
arshsmith1:speling-uri-underflow
Open

arshsmith1 wants to merge 1 commit into
apache:trunkfrom
arshsmith1:speling-uri-underflow

Conversation

@arshsmith1

Copy link
Copy Markdown

check_speling() assumes postgood (the mapped file base name plus any PATH_INFO) is a trailing substring of r->uri, but nothing enforces that before it computes r->uri + (urlen - pglen) for the suffix compare. When a mapper such as Alias or a RewriteRule points a short URI at a nonexistent file whose base name is longer, pglen exceeds urlen, the int subtraction goes negative, and the strcmp reads before the start of the r->uri buffer (the apr_pstrndup that follows also gets a negative length). Returning DECLINED when pglen > urlen keeps the compare in bounds and leaves the normal suffix case unchanged.

AI tooling was used to help prepare this change.

@notroj

notroj commented Sep 30, 2026

Copy link
Copy Markdown
Collaborator

Thanks. Any chance of a test case as well?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants