mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-10-01 06:21:56 -09:00
package/squid: backport patch for CVE-2026-33526
- CVE-2026-33526:
Squid is a caching proxy for the Web. Prior to version 7.5, due to
heap Use-After-Free, Squid is vulnerable to Denial of Service when
handling ICP traffic. This problem allows a remote attacker to perform
a reliable and repeatable Denial of Service attack against the Squid
service using ICP protocol. This attack is limited to Squid
deployments that explicitly enable ICP support (i.e. configure non-
zero `icp_port`). This problem _cannot_ be mitigated by denying ICP
queries using `icp_access` rules. Version 7.5 contains a patch.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2026-33526
- 8138e909d2
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
This commit is contained in:
34
package/squid/0004-CVE-2026-33526.patch
Normal file
34
package/squid/0004-CVE-2026-33526.patch
Normal file
@@ -0,0 +1,34 @@
|
|||||||
|
From 8a7d42f9d44befb8fcbbb619505587c8de6a1e91 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Joshua Rogers <megamansec@gmail.com>
|
||||||
|
Date: Tue, 10 Feb 2026 19:58:49 +0000
|
||||||
|
Subject: [PATCH] Do not escape malformed URI twice when sending ICP errors
|
||||||
|
(#2374)
|
||||||
|
|
||||||
|
In this context, escaping escaped URI always produces incorrect URI
|
||||||
|
because `%` character in the escaped URI gets escaped again. Feeding the
|
||||||
|
result of the first rfc1738_escape() call to the second call is also
|
||||||
|
dangerously wrong because the result of the first call gets invalidated
|
||||||
|
during the second call.
|
||||||
|
|
||||||
|
No other cases of such "chained" rfc1738_escape() calls were found.
|
||||||
|
|
||||||
|
Broken since 2002 commit e6ccf245.
|
||||||
|
Upstream: https://github.com/squid-cache/squid/commit/8138e909d2058d4401e0ad49b583afaec912b165
|
||||||
|
CVE: CVE-2026-33526
|
||||||
|
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
|
||||||
|
---
|
||||||
|
src/icp_v2.cc | 1 -
|
||||||
|
1 file changed, 1 deletion(-)
|
||||||
|
|
||||||
|
diff --git a/src/icp_v2.cc b/src/icp_v2.cc
|
||||||
|
index 2a4ced3bfab..25f7b71d25e 100644
|
||||||
|
--- a/src/icp_v2.cc
|
||||||
|
+++ b/src/icp_v2.cc
|
||||||
|
@@ -490,7 +490,6 @@ HttpRequest *
|
||||||
|
icpGetRequest(const char * const url, const int reqnum, const int fd, const Ip::Address &from)
|
||||||
|
{
|
||||||
|
if (strpbrk(url, w_space)) {
|
||||||
|
- url = rfc1738_escape(url);
|
||||||
|
icpCreateAndSend(ICP_ERR, 0, rfc1738_escape(url), reqnum, 0, fd, from, nullptr);
|
||||||
|
return nullptr;
|
||||||
|
}
|
||||||
@@ -21,6 +21,9 @@ SQUID_IGNORE_CVES += CVE-2025-62168
|
|||||||
# 0003-CVE-2026-33515.patch
|
# 0003-CVE-2026-33515.patch
|
||||||
SQUID_IGNORE_CVES += CVE-2026-33515
|
SQUID_IGNORE_CVES += CVE-2026-33515
|
||||||
|
|
||||||
|
# 0004-CVE-2026-33526.patch
|
||||||
|
SQUID_IGNORE_CVES += CVE-2026-33526
|
||||||
|
|
||||||
SQUID_DEPENDENCIES = libcap host-libcap libtool libxml2 host-pkgconf \
|
SQUID_DEPENDENCIES = libcap host-libcap libtool libxml2 host-pkgconf \
|
||||||
$(if $(BR2_PACKAGE_LIBNETFILTER_CONNTRACK),libnetfilter_conntrack)
|
$(if $(BR2_PACKAGE_LIBNETFILTER_CONNTRACK),libnetfilter_conntrack)
|
||||||
SQUID_CONF_ENV = \
|
SQUID_CONF_ENV = \
|
||||||
|
|||||||
Reference in New Issue
Block a user