Bug 34216 - apache-mod_auth_openidc new security issue CVE-2025-31492
Summary: apache-mod_auth_openidc new security issue CVE-2025-31492
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-04-22 14:08 CEST by Nicolas Salguero
Modified: 2025-05-05 06:59 CEST (History)
3 users (show)

See Also:
Source RPM: apache-mod_auth_openidc-2.4.13.2-1.1.mga9.src.rpm
CVE: CVE-2025-31492
Status comment:


Attachments

Description Nicolas Salguero 2025-04-22 14:08:19 CEST
openSUSE has issued an advisory on April 15:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/4RNEMKHJH72IHWVOIEQAKSXHOSDXQN3A/

Debian has issued an advisory on April 17:
https://lists.debian.org/debian-security-announce/2025/msg00066.html
Nicolas Salguero 2025-04-22 14:09:04 CEST

Status comment: (none) => Patches available from Debian and openSUSE
CVE: (none) => CVE-2025-31492
Source RPM: (none) => apache-mod_auth_openidc-2.4.15.6-1.mga10.src.rpm, apache-mod_auth_openidc-2.4.13.2-1.1.mga9.src.rpm
Whiteboard: (none) => MGA9TOO

Comment 2 Lewis Smith 2025-04-23 11:25:43 CEST
Chasing Suse:
https://github.com/OpenIDC/mod_auth_openidc/security/advisories/GHSA-59jp-rwph-878r
says "The issue has been patched in mod_auth_openidc versions >= 2.4.16.11."

and:
https://github.com/OpenIDC/mod_auth_openidc/commit/b59b8ad63411857090ba1088e23fe414c690c127
is their patch.

https://bugzilla.suse.com/show_bug.cgi?id=1240893#c19
says "I have verified that the testcase gives BEFORE [fault] for 2.4.16.10 and AFTER [OK] for 2.4.16.11" re previous comment.
For QA, I would believe them!

Looks like another version update. Assigning to Nicolas who has done recent CVE version updates.

Assignee: bugsquad => nicolas.salguero

Nicolas Salguero 2025-04-23 15:03:56 CEST

Assignee: nicolas.salguero => pkg-bugs

Comment 3 Nicolas Salguero 2025-04-24 16:52:27 CEST
Ubuntu has issued an advisory on April 23:
https://ubuntu.com/security/notices/USN-7446-1
Comment 4 Nicolas Salguero 2025-04-29 15:51:28 CEST
Suggested advisory:
========================

The updated package fixes a security vulnerability:

mod_auth_openidc allows OIDCProviderAuthRequestMethod POSTs to leak protected data. (CVE-2025-31492)

References:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/4RNEMKHJH72IHWVOIEQAKSXHOSDXQN3A/
https://lists.debian.org/debian-security-announce/2025/msg00066.html
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3Z7RSITAKS2ICGANCQP2TDUHMS2LZDXR/
https://ubuntu.com/security/notices/USN-7446-1
========================

Updated package in core/updates_testing:
========================
apache-mod_auth_openidc-2.4.13.2-1.2.mga9

from SRPM:
apache-mod_auth_openidc-2.4.13.2-1.2.mga9.src.rpm

Status: NEW => ASSIGNED
Source RPM: apache-mod_auth_openidc-2.4.15.6-1.mga10.src.rpm, apache-mod_auth_openidc-2.4.13.2-1.1.mga9.src.rpm => apache-mod_auth_openidc-2.4.13.2-1.1.mga9.src.rpm
Whiteboard: MGA9TOO => (none)
Assignee: pkg-bugs => qa-bugs
Version: Cauldron => 9
Status comment: Patches available from Debian and openSUSE => (none)

katnatek 2025-04-29 19:50:25 CEST

Keywords: (none) => advisory

Comment 5 Herman Viaene 2025-05-01 15:55:48 CEST
MGA9-64 Plasma Wayland on Compaq H000SB.
No installation issues.
Ref bug 29344 for testing:
# systemctl start httpd
# systemctl -l status httpd
● httpd.service - The Apache HTTP Server
     Loaded: loaded (/usr/lib/systemd/system/httpd.service; disabled; preset: disabled)
     Active: active (running) since Thu 2025-05-01 15:52:08 CEST; 13s ago
   Main PID: 344197 (/usr/sbin/httpd)
     Status: "Total requests: 0; Idle/Busy workers 100/0;Requests/sec: 0; Bytes served/sec:   0 B/sec"
      Tasks: 6 (limit: 8806)
     Memory: 27.0M
        CPU: 676ms
     CGroup: /system.slice/httpd.service
             ├─344197 /usr/sbin/httpd -DFOREGROUND
             ├─344200 /usr/sbin/httpd -DFOREGROUND
             ├─344201 /usr/sbin/httpd -DFOREGROUND
             ├─344202 /usr/sbin/httpd -DFOREGROUND
             ├─344203 /usr/sbin/httpd -DFOREGROUND
             └─344204 /usr/sbin/httpd -DFOREGROUND

May 01 15:52:08 mach3.hviaene.thuis systemd[1]: Starting httpd.service...
May 01 15:52:08 mach3.hviaene.thuis systemd[1]: Started httpd.service.

Pointed browser to localhost and got "It works!"
OK for me.

Whiteboard: (none) => MGA9-64-OK
CC: (none) => herman.viaene

Comment 6 Thomas Andrews 2025-05-02 01:06:42 CEST
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Comment 7 Mageia Robot 2025-05-05 06:59:07 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0147.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.