package/squid: add upstream patch CVE-2026-47729

- CVE-2026-47729
    Due to a Improper Validation of Syntactic Correctness of Input bug,
    Squid is vulnerable to a Out-of-bounds Read attack against the FTP
    gateway.

    This problem allows a trusted client to perform an Out-of-Bounds
    Read from random unrelated transactions when accessing a misbehaving
    FTP server through Squid's gateway feature.

For more information, see:
 - https://blog.calif.io/p/squidbleed-cve-2026-47729
 - https://www.openwall.com/lists/oss-security/2026/06/12/1
 - 865a131c7d

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
This commit is contained in:
Thomas Perale
2026-06-26 10:28:51 +02:00
parent 7938b9236b
commit 925b128549
2 changed files with 52 additions and 0 deletions

View File

@@ -0,0 +1,49 @@
From 865a131c7d557e68c965043d98c2eccae26deef8 Mon Sep 17 00:00:00 2001
From: squidadm <squidadm@users.noreply.github.com>
Date: Sun, 17 May 2026 18:04:47 +1200
Subject: [PATCH] Improve parsing of certain FTP directory listing formats
(#2408) (#2409)
This surgical fix restricts parsing to the input buffer when the listing
entry date in "TypeA" or "TypeB" formats is not followed by a filename.
It does not improve rendering of listings with missing filenames or the
overall quality of FTP listing parsing code.
C strchr() always returns a non-nil pointer when given a NUL character,
so its callers must be careful not to supply a NUL character if a
"natural" one-of-the-regular-c-string-characters membership test is
required.
The bug was probably introduced in 1997 commit 3fdadc70 and then
duplicated in 2017 commit 3d872090.
Co-authored-by: Alex Rousskov <rousskov@measurement-factory.com>
Co-authored-by: Amos Jeffries <yadij@users.noreply.github.com>
Upstream: https://github.com/squid-cache/squid/commit/865a131c7d557e68c965043d98c2eccae26deef8
CVE: CVE-2026-47729
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
---
src/clients/FtpGateway.cc | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/src/clients/FtpGateway.cc b/src/clients/FtpGateway.cc
index 164fd0e499c..e04bb603d96 100644
--- a/src/clients/FtpGateway.cc
+++ b/src/clients/FtpGateway.cc
@@ -622,7 +622,7 @@ ftpListParseParts(const char *buf, struct Ftp::GatewayFlags flags)
// point after tokens[i+2] :
copyFrom = buf + tokens[i + 2].pos + strlen(tokens[i + 2].token);
if (flags.skip_whitespace) {
- while (strchr(w_space, *copyFrom))
+ while (*copyFrom && strchr(w_space, *copyFrom))
++copyFrom;
} else {
/* Handle the following four formats:
@@ -633,7 +633,7 @@ ftpListParseParts(const char *buf, struct Ftp::GatewayFlags flags)
* Assuming a single space between date and filename
* suggested by: Nathan.Bailey@cc.monash.edu.au and
* Mike Battersby <mike@starbug.bofh.asn.au> */
- if (strchr(w_space, *copyFrom))
+ if (*copyFrom && strchr(w_space, *copyFrom))
++copyFrom;
}

View File

@@ -24,6 +24,9 @@ SQUID_IGNORE_CVES += CVE-2026-33515
# 0004-CVE-2026-33526.patch
SQUID_IGNORE_CVES += CVE-2026-33526
# 0005-CVE-2026-47729.patch
SQUID_IGNORE_CVES += CVE-2026-47729
SQUID_DEPENDENCIES = libcap host-libcap libtool libxml2 host-pkgconf \
$(if $(BR2_PACKAGE_LIBNETFILTER_CONNTRACK),libnetfilter_conntrack)
SQUID_CONF_ENV = \