Out-of-bounds read in mod_auth_openidc - CVE-2026-54789

 

Out-of-bounds read in mod_auth_openidc - CVE-2026-54789

Published: July 2, 2026


Vulnerability identifier: #VU136688
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54789
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition in the state-cookie parser of mod_auth_openidc. A remote attacker can trigger an out-of-bounds read error and cause a denial of service condition on the system.


Affected software

mod_auth_openidc
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
openEuler
apache2-mod_auth_openidc-debuginfo
apache2-mod_auth_openidc
apache2-mod_auth_openidc-debugsource
mod_auth_openidc
mod_auth_openidc-debuginfo
mod_auth_openidc-debugsource

How to mitigate CVE-2026-54789

Install updates from vendor's website.

mod_auth_openidc - update to 2.4.19.4
apache2-mod_auth_openidc-debuginfo - update to 2.4.0-7.25.1
apache2-mod_auth_openidc - update to 2.4.0-7.25.1
apache2-mod_auth_openidc-debugsource - update to 2.4.0-7.25.1
mod_auth_openidc - update to 2.4.19.4-1
mod_auth_openidc-debuginfo - update to 2.4.19.4-1
mod_auth_openidc-debugsource - update to 2.4.19.4-1

External References

Related Security Bulletins