mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-10-01 06:21:56 -09:00
package/squid: add upstream patch for CVE-2026-50012
- CVE-2026-50012
Due to an Improper Input Validation bug, Squid is vulnerable to a
Heap-based Buffer Overflow attack against cache digests.
For more information, see:
- https://github.com/squid-cache/squid/security/advisories/GHSA-5vmx-9x64-9284
- 19fcfe9227
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
This commit is contained in:
33
package/squid/0006-CVE-2026-50012.patch
Normal file
33
package/squid/0006-CVE-2026-50012.patch
Normal file
@@ -0,0 +1,33 @@
|
|||||||
|
From 19fcfe922717c8b255270c032dcde4071c003bcd Mon Sep 17 00:00:00 2001
|
||||||
|
From: Francesco Chemolli <5175948+kinkie@users.noreply.github.com>
|
||||||
|
Date: Sat, 30 May 2026 10:16:33 +0000
|
||||||
|
Subject: [PATCH] Harden peerDigestSwapInMask against invalid cache digest
|
||||||
|
reply (#2423)
|
||||||
|
|
||||||
|
A cache_digest on-the-wire size may be bigger than the
|
||||||
|
mask_size declared in the digest itself.
|
||||||
|
|
||||||
|
Ignore the digest in case this happens.
|
||||||
|
Upstream: https://github.com/squid-cache/squid/commit/19fcfe922717c8b255270c032dcde4071c003bcd
|
||||||
|
CVE: CVE-2026-50012
|
||||||
|
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
|
||||||
|
---
|
||||||
|
src/peer_digest.cc | 5 +++++
|
||||||
|
1 file changed, 5 insertions(+)
|
||||||
|
|
||||||
|
diff --git a/src/peer_digest.cc b/src/peer_digest.cc
|
||||||
|
index 741090574d6..53dac203eab 100644
|
||||||
|
--- a/src/peer_digest.cc
|
||||||
|
+++ b/src/peer_digest.cc
|
||||||
|
@@ -622,6 +622,11 @@ peerDigestSwapInMask(void *data, char *buf, ssize_t size)
|
||||||
|
* NOTENOTENOTENOTENOTE: buf doesn't point to pd->cd->mask anymore!
|
||||||
|
* we need to do the copy ourselves!
|
||||||
|
*/
|
||||||
|
+ Assure(size >= 0);
|
||||||
|
+ if (fetch->mask_offset + size > static_cast<ssize_t>(pd->cd->mask_size)) {
|
||||||
|
+ finishAndDeleteFetch(fetch, "peer digest mask data too large", true);
|
||||||
|
+ return -1;
|
||||||
|
+ }
|
||||||
|
memcpy(pd->cd->mask + fetch->mask_offset, buf, size);
|
||||||
|
|
||||||
|
/* NOTE! buf points to the middle of pd->cd->mask! */
|
||||||
@@ -27,6 +27,9 @@ SQUID_IGNORE_CVES += CVE-2026-33526
|
|||||||
# 0005-CVE-2026-47729.patch
|
# 0005-CVE-2026-47729.patch
|
||||||
SQUID_IGNORE_CVES += CVE-2026-47729
|
SQUID_IGNORE_CVES += CVE-2026-47729
|
||||||
|
|
||||||
|
# 0006-CVE-2026-50012.patch
|
||||||
|
SQUID_IGNORE_CVES += CVE-2026-50012
|
||||||
|
|
||||||
SQUID_DEPENDENCIES = libcap host-libcap libtool libxml2 host-pkgconf \
|
SQUID_DEPENDENCIES = libcap host-libcap libtool libxml2 host-pkgconf \
|
||||||
$(if $(BR2_PACKAGE_LIBNETFILTER_CONNTRACK),libnetfilter_conntrack)
|
$(if $(BR2_PACKAGE_LIBNETFILTER_CONNTRACK),libnetfilter_conntrack)
|
||||||
SQUID_CONF_ENV = \
|
SQUID_CONF_ENV = \
|
||||||
|
|||||||
Reference in New Issue
Block a user