From 7938b9236b0b5e69b25f583056942ad5d604785b Mon Sep 17 00:00:00 2001 From: Thomas Perale Date: Fri, 26 Jun 2026 10:28:50 +0200 Subject: [PATCH] package/squid: backport patch for CVE-2026-33526 - CVE-2026-33526: Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non- zero `icp_port`). This problem _cannot_ be mitigated by denying ICP queries using `icp_access` rules. Version 7.5 contains a patch. For more information, see: - https://www.cve.org/CVERecord?id=CVE-2026-33526 - https://github.com/squid-cache/squid/commit/8138e909d2058d4401e0ad49b583afaec912b165 Signed-off-by: Thomas Perale --- package/squid/0004-CVE-2026-33526.patch | 34 +++++++++++++++++++++++++ package/squid/squid.mk | 3 +++ 2 files changed, 37 insertions(+) create mode 100644 package/squid/0004-CVE-2026-33526.patch diff --git a/package/squid/0004-CVE-2026-33526.patch b/package/squid/0004-CVE-2026-33526.patch new file mode 100644 index 0000000000..572a0197cb --- /dev/null +++ b/package/squid/0004-CVE-2026-33526.patch @@ -0,0 +1,34 @@ +From 8a7d42f9d44befb8fcbbb619505587c8de6a1e91 Mon Sep 17 00:00:00 2001 +From: Joshua Rogers +Date: Tue, 10 Feb 2026 19:58:49 +0000 +Subject: [PATCH] Do not escape malformed URI twice when sending ICP errors + (#2374) + +In this context, escaping escaped URI always produces incorrect URI +because `%` character in the escaped URI gets escaped again. Feeding the +result of the first rfc1738_escape() call to the second call is also +dangerously wrong because the result of the first call gets invalidated +during the second call. + +No other cases of such "chained" rfc1738_escape() calls were found. + +Broken since 2002 commit e6ccf245. +Upstream: https://github.com/squid-cache/squid/commit/8138e909d2058d4401e0ad49b583afaec912b165 +CVE: CVE-2026-33526 +Signed-off-by: Thomas Perale +--- + src/icp_v2.cc | 1 - + 1 file changed, 1 deletion(-) + +diff --git a/src/icp_v2.cc b/src/icp_v2.cc +index 2a4ced3bfab..25f7b71d25e 100644 +--- a/src/icp_v2.cc ++++ b/src/icp_v2.cc +@@ -490,7 +490,6 @@ HttpRequest * + icpGetRequest(const char * const url, const int reqnum, const int fd, const Ip::Address &from) + { + if (strpbrk(url, w_space)) { +- url = rfc1738_escape(url); + icpCreateAndSend(ICP_ERR, 0, rfc1738_escape(url), reqnum, 0, fd, from, nullptr); + return nullptr; + } diff --git a/package/squid/squid.mk b/package/squid/squid.mk index 4a56e32e59..e072ec6137 100644 --- a/package/squid/squid.mk +++ b/package/squid/squid.mk @@ -21,6 +21,9 @@ SQUID_IGNORE_CVES += CVE-2025-62168 # 0003-CVE-2026-33515.patch SQUID_IGNORE_CVES += CVE-2026-33515 +# 0004-CVE-2026-33526.patch +SQUID_IGNORE_CVES += CVE-2026-33526 + SQUID_DEPENDENCIES = libcap host-libcap libtool libxml2 host-pkgconf \ $(if $(BR2_PACKAGE_LIBNETFILTER_CONNTRACK),libnetfilter_conntrack) SQUID_CONF_ENV = \