package/squid: backport patch for CVE-2026-33526

- CVE-2026-33526:
    Squid is a caching proxy for the Web. Prior to version 7.5, due to
    heap Use-After-Free, Squid is vulnerable to Denial of Service when
    handling ICP traffic. This problem allows a remote attacker to perform
    a reliable and repeatable Denial of Service attack against the Squid
    service using ICP protocol. This attack is limited to Squid
    deployments that explicitly enable ICP support (i.e. configure non-
    zero `icp_port`). This problem _cannot_ be mitigated by denying ICP
    queries using `icp_access` rules. Version 7.5 contains a patch.

For more information, see:
  - https://www.cve.org/CVERecord?id=CVE-2026-33526
  - 8138e909d2

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
This commit is contained in:
Thomas Perale
2026-06-26 10:28:50 +02:00
parent 6401cd531a
commit 7938b9236b
2 changed files with 37 additions and 0 deletions

View File

@@ -0,0 +1,34 @@
From 8a7d42f9d44befb8fcbbb619505587c8de6a1e91 Mon Sep 17 00:00:00 2001
From: Joshua Rogers <megamansec@gmail.com>
Date: Tue, 10 Feb 2026 19:58:49 +0000
Subject: [PATCH] Do not escape malformed URI twice when sending ICP errors
(#2374)
In this context, escaping escaped URI always produces incorrect URI
because `%` character in the escaped URI gets escaped again. Feeding the
result of the first rfc1738_escape() call to the second call is also
dangerously wrong because the result of the first call gets invalidated
during the second call.
No other cases of such "chained" rfc1738_escape() calls were found.
Broken since 2002 commit e6ccf245.
Upstream: https://github.com/squid-cache/squid/commit/8138e909d2058d4401e0ad49b583afaec912b165
CVE: CVE-2026-33526
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
---
src/icp_v2.cc | 1 -
1 file changed, 1 deletion(-)
diff --git a/src/icp_v2.cc b/src/icp_v2.cc
index 2a4ced3bfab..25f7b71d25e 100644
--- a/src/icp_v2.cc
+++ b/src/icp_v2.cc
@@ -490,7 +490,6 @@ HttpRequest *
icpGetRequest(const char * const url, const int reqnum, const int fd, const Ip::Address &from)
{
if (strpbrk(url, w_space)) {
- url = rfc1738_escape(url);
icpCreateAndSend(ICP_ERR, 0, rfc1738_escape(url), reqnum, 0, fd, from, nullptr);
return nullptr;
}

View File

@@ -21,6 +21,9 @@ SQUID_IGNORE_CVES += CVE-2025-62168
# 0003-CVE-2026-33515.patch
SQUID_IGNORE_CVES += CVE-2026-33515
# 0004-CVE-2026-33526.patch
SQUID_IGNORE_CVES += CVE-2026-33526
SQUID_DEPENDENCIES = libcap host-libcap libtool libxml2 host-pkgconf \
$(if $(BR2_PACKAGE_LIBNETFILTER_CONNTRACK),libnetfilter_conntrack)
SQUID_CONF_ENV = \