From: Rainer Jung Date: Wed, 17 Jun 2026 09:44:36 +0000 (+0000) Subject: mod_md: change types of fields of ocsp_summary_ctx_t X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=ad449e35a46f2d9f08dd4b5ca3ec0e6ad18192a5;p=thirdparty%2Fapache%2Fhttpd.git mod_md: change types of fields of ocsp_summary_ctx_t The number of members in ostat_by_id may be up to UINT_MAX and there are no guarantees that all types of members (good, revoked or unknown) are present. An integer overflow may also occur in md_ocsp_get_summary() when they are summed as ints. Change types of good, revoked and unknown to unsigned. Found by Linux Verification Center (linuxtesting.org) with SVACE. Submitted by: Anastasia Belova Github: closes #534 Backport of r1930710 from trunk, [mod_md CTR] git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.4.x@1935448 13f79535-47bb-0310-9956-ffa450edef68 --- diff --git a/modules/md/md_ocsp.c b/modules/md/md_ocsp.c index b44458676f..aee799a7b3 100644 --- a/modules/md/md_ocsp.c +++ b/modules/md/md_ocsp.c @@ -950,9 +950,9 @@ apr_status_t md_ocsp_remove_responses_older_than(md_ocsp_reg_t *reg, apr_pool_t typedef struct { apr_pool_t *p; md_ocsp_reg_t *reg; - int good; - int revoked; - int unknown; + unsigned good; + unsigned revoked; + unsigned unknown; } ocsp_summary_ctx_t; static int add_to_summary(void *baton, const void *key, apr_ssize_t klen, const void *val)