mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-29 13:31:43 -09:00
package/squid: add upstream patch CVE-2026-47729
- CVE-2026-47729
Due to a Improper Validation of Syntactic Correctness of Input bug,
Squid is vulnerable to a Out-of-bounds Read attack against the FTP
gateway.
This problem allows a trusted client to perform an Out-of-Bounds
Read from random unrelated transactions when accessing a misbehaving
FTP server through Squid's gateway feature.
For more information, see:
- https://blog.calif.io/p/squidbleed-cve-2026-47729
- https://www.openwall.com/lists/oss-security/2026/06/12/1
- 865a131c7d
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
This commit is contained in:
49
package/squid/0005-CVE-2026-47729.patch
Normal file
49
package/squid/0005-CVE-2026-47729.patch
Normal file
@@ -0,0 +1,49 @@
|
||||
From 865a131c7d557e68c965043d98c2eccae26deef8 Mon Sep 17 00:00:00 2001
|
||||
From: squidadm <squidadm@users.noreply.github.com>
|
||||
Date: Sun, 17 May 2026 18:04:47 +1200
|
||||
Subject: [PATCH] Improve parsing of certain FTP directory listing formats
|
||||
(#2408) (#2409)
|
||||
|
||||
This surgical fix restricts parsing to the input buffer when the listing
|
||||
entry date in "TypeA" or "TypeB" formats is not followed by a filename.
|
||||
It does not improve rendering of listings with missing filenames or the
|
||||
overall quality of FTP listing parsing code.
|
||||
|
||||
C strchr() always returns a non-nil pointer when given a NUL character,
|
||||
so its callers must be careful not to supply a NUL character if a
|
||||
"natural" one-of-the-regular-c-string-characters membership test is
|
||||
required.
|
||||
|
||||
The bug was probably introduced in 1997 commit 3fdadc70 and then
|
||||
duplicated in 2017 commit 3d872090.
|
||||
|
||||
Co-authored-by: Alex Rousskov <rousskov@measurement-factory.com>
|
||||
Co-authored-by: Amos Jeffries <yadij@users.noreply.github.com>
|
||||
Upstream: https://github.com/squid-cache/squid/commit/865a131c7d557e68c965043d98c2eccae26deef8
|
||||
CVE: CVE-2026-47729
|
||||
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
|
||||
---
|
||||
src/clients/FtpGateway.cc | 4 ++--
|
||||
1 file changed, 2 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/clients/FtpGateway.cc b/src/clients/FtpGateway.cc
|
||||
index 164fd0e499c..e04bb603d96 100644
|
||||
--- a/src/clients/FtpGateway.cc
|
||||
+++ b/src/clients/FtpGateway.cc
|
||||
@@ -622,7 +622,7 @@ ftpListParseParts(const char *buf, struct Ftp::GatewayFlags flags)
|
||||
// point after tokens[i+2] :
|
||||
copyFrom = buf + tokens[i + 2].pos + strlen(tokens[i + 2].token);
|
||||
if (flags.skip_whitespace) {
|
||||
- while (strchr(w_space, *copyFrom))
|
||||
+ while (*copyFrom && strchr(w_space, *copyFrom))
|
||||
++copyFrom;
|
||||
} else {
|
||||
/* Handle the following four formats:
|
||||
@@ -633,7 +633,7 @@ ftpListParseParts(const char *buf, struct Ftp::GatewayFlags flags)
|
||||
* Assuming a single space between date and filename
|
||||
* suggested by: Nathan.Bailey@cc.monash.edu.au and
|
||||
* Mike Battersby <mike@starbug.bofh.asn.au> */
|
||||
- if (strchr(w_space, *copyFrom))
|
||||
+ if (*copyFrom && strchr(w_space, *copyFrom))
|
||||
++copyFrom;
|
||||
}
|
||||
@@ -24,6 +24,9 @@ SQUID_IGNORE_CVES += CVE-2026-33515
|
||||
# 0004-CVE-2026-33526.patch
|
||||
SQUID_IGNORE_CVES += CVE-2026-33526
|
||||
|
||||
# 0005-CVE-2026-47729.patch
|
||||
SQUID_IGNORE_CVES += CVE-2026-47729
|
||||
|
||||
SQUID_DEPENDENCIES = libcap host-libcap libtool libxml2 host-pkgconf \
|
||||
$(if $(BR2_PACKAGE_LIBNETFILTER_CONNTRACK),libnetfilter_conntrack)
|
||||
SQUID_CONF_ENV = \
|
||||
|
||||
Reference in New Issue
Block a user