Nginx CGI v0.15.2 Fixes Request Hangs and Memory-Safety Bug

Published by

Chizhong Jin has released version 0.15.2 of Nginx CGI, addressing two significant issues: a request hang related to large POST bodies and a memory-safety bug due to missing null-termination in constant cgi_set_var values. The hang issue caused requests to stall indefinitely when the request body exceeded the client_body_buffer_size, while the memory-safety fix prevents potential data leaks and crashes from unterminated strings. This release emphasizes security hardening, following previous updates that removed potentially vulnerable environment variables. Administrators using CGI in production environments are encouraged to upgrade to this version to mitigate these vulnerabilities, especially when handling large request bodies or constant configuration values



Nginx CGI v0.15.2 Fixes Request Hangs and Memory-Safety Bug

Chizhong Jin released v0.15.2 of Nginx CGI, fixing two bugs that could leave requests hung or leak memory. The hang fix resolves an issue where request bodies larger than client_body_buffer_size would stall indefinitely once the in-memory buffer was drained. The memory-safety patch closes a missing null-termination gap in constant cgi_set_var values, a follow-up to work from the previous release. Admins running CGI in production, especially those handling large POST bodies or constant config variables, should upgrade to close both gaps.

Nginx CGI v0.15.2 Fixes Request Hangs and Memory-Safety Bug @ Linux Compatible