mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-29 21:41:43 -09:00
package/squid: backport patch for CVE-2026-33526
- CVE-2026-33526:
Squid is a caching proxy for the Web. Prior to version 7.5, due to
heap Use-After-Free, Squid is vulnerable to Denial of Service when
handling ICP traffic. This problem allows a remote attacker to perform
a reliable and repeatable Denial of Service attack against the Squid
service using ICP protocol. This attack is limited to Squid
deployments that explicitly enable ICP support (i.e. configure non-
zero `icp_port`). This problem _cannot_ be mitigated by denying ICP
queries using `icp_access` rules. Version 7.5 contains a patch.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2026-33526
- 8138e909d2
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
This commit is contained in:
34
package/squid/0004-CVE-2026-33526.patch
Normal file
34
package/squid/0004-CVE-2026-33526.patch
Normal file
@@ -0,0 +1,34 @@
|
||||
From 8a7d42f9d44befb8fcbbb619505587c8de6a1e91 Mon Sep 17 00:00:00 2001
|
||||
From: Joshua Rogers <megamansec@gmail.com>
|
||||
Date: Tue, 10 Feb 2026 19:58:49 +0000
|
||||
Subject: [PATCH] Do not escape malformed URI twice when sending ICP errors
|
||||
(#2374)
|
||||
|
||||
In this context, escaping escaped URI always produces incorrect URI
|
||||
because `%` character in the escaped URI gets escaped again. Feeding the
|
||||
result of the first rfc1738_escape() call to the second call is also
|
||||
dangerously wrong because the result of the first call gets invalidated
|
||||
during the second call.
|
||||
|
||||
No other cases of such "chained" rfc1738_escape() calls were found.
|
||||
|
||||
Broken since 2002 commit e6ccf245.
|
||||
Upstream: https://github.com/squid-cache/squid/commit/8138e909d2058d4401e0ad49b583afaec912b165
|
||||
CVE: CVE-2026-33526
|
||||
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
|
||||
---
|
||||
src/icp_v2.cc | 1 -
|
||||
1 file changed, 1 deletion(-)
|
||||
|
||||
diff --git a/src/icp_v2.cc b/src/icp_v2.cc
|
||||
index 2a4ced3bfab..25f7b71d25e 100644
|
||||
--- a/src/icp_v2.cc
|
||||
+++ b/src/icp_v2.cc
|
||||
@@ -490,7 +490,6 @@ HttpRequest *
|
||||
icpGetRequest(const char * const url, const int reqnum, const int fd, const Ip::Address &from)
|
||||
{
|
||||
if (strpbrk(url, w_space)) {
|
||||
- url = rfc1738_escape(url);
|
||||
icpCreateAndSend(ICP_ERR, 0, rfc1738_escape(url), reqnum, 0, fd, from, nullptr);
|
||||
return nullptr;
|
||||
}
|
||||
@@ -21,6 +21,9 @@ SQUID_IGNORE_CVES += CVE-2025-62168
|
||||
# 0003-CVE-2026-33515.patch
|
||||
SQUID_IGNORE_CVES += CVE-2026-33515
|
||||
|
||||
# 0004-CVE-2026-33526.patch
|
||||
SQUID_IGNORE_CVES += CVE-2026-33526
|
||||
|
||||
SQUID_DEPENDENCIES = libcap host-libcap libtool libxml2 host-pkgconf \
|
||||
$(if $(BR2_PACKAGE_LIBNETFILTER_CONNTRACK),libnetfilter_conntrack)
|
||||
SQUID_CONF_ENV = \
|
||||
|
||||
Reference in New Issue
Block a user