From 12d5c032dfd6e2573cf310625aa591a27b67d960 Mon Sep 17 00:00:00 2001 From: arshiya tabasum Date: Thu, 1 Oct 2026 13:20:25 +0530 Subject: [PATCH] mod_authnz_fcgi: bound stderr log to the received length --- changes-entries/authnz-fcgi-stderr-bound.txt | 3 +++ modules/aaa/mod_authnz_fcgi.c | 4 ++-- 2 files changed, 5 insertions(+), 2 deletions(-) create mode 100644 changes-entries/authnz-fcgi-stderr-bound.txt diff --git a/changes-entries/authnz-fcgi-stderr-bound.txt b/changes-entries/authnz-fcgi-stderr-bound.txt new file mode 100644 index 00000000000..54530bb9a99 --- /dev/null +++ b/changes-entries/authnz-fcgi-stderr-bound.txt @@ -0,0 +1,3 @@ + *) mod_authnz_fcgi: Log the content of a FastCGI stderr record using its + received length instead of treating the buffer as a C string, avoiding a + read past the received bytes. [arshiya tabasum] diff --git a/modules/aaa/mod_authnz_fcgi.c b/modules/aaa/mod_authnz_fcgi.c index 7881738ed67..813dddc2ef8 100644 --- a/modules/aaa/mod_authnz_fcgi.c +++ b/modules/aaa/mod_authnz_fcgi.c @@ -629,8 +629,8 @@ static apr_status_t handle_response(const fcgi_provider_conf *conf, case AP_FCGI_STDERR: /* Text to log */ if (clen) { ap_log_rerror(APLOG_MARK, APLOG_WARNING, 0, r, - APLOGNO(02507) "%s: Logged from %s: '%s'", - fn, conf->backend, readbuf); + APLOGNO(02507) "%s: Logged from %s: '%.*s'", + fn, conf->backend, (int)readbuflen, readbuf); } if (clen > readbuflen) {