[CLSA-2026:1784710881] Fix CVE(s): CVE-2026-47729, CVE-2026-50012
Type:
security
Severity:
Moderate
Release date:
2026-07-22 09:01:49 UTC
Description:
* SECURITY UPDATE: out-of-bounds read in the FTP gateway directory-listing parser when a TypeA/TypeB listing entry date is not followed by a filename - debian/patches/CVE-2026-47729.patch: restrict parsing to the input buffer in ftpListParseParts() by checking for a NUL byte before strchr(w_space) in src/clients/FtpGateway.cc - CVE-2026-47729 * SECURITY UPDATE: heap-based buffer overflow in cache digest reply handling when a peer reply's on-the-wire size exceeds the declared mask_size - debian/patches/CVE-2026-50012.patch: bound-check mask_offset + size against mask_size before memcpy() in peerDigestSwapInMask() and abort the fetch on overflow in src/peer_digest.cc - CVE-2026-50012
Updated packages:
  • squid_4.6-1+deb10u10+tuxcare.els5_amd64.deb
    sha:4423a492ec1eb395a62fb21fd3cb137b34c8af3b
  • squid-cgi_4.6-1+deb10u10+tuxcare.els5_amd64.deb
    sha:099653c1d9ec386db0217f10d16c30d4be98a986
  • squid-common_4.6-1+deb10u10+tuxcare.els5_all.deb
    sha:7d96106b16a8660a628688dd6f000fb458f8cfc0
  • squid-purge_4.6-1+deb10u10+tuxcare.els5_amd64.deb
    sha:8a13807ae59aebce90cc62694245aa1214acf666
  • squid3_4.6-1+deb10u10+tuxcare.els5_all.deb
    sha:180bbe62532dc5b35cbfcfe5ca21b602a6a84cf3
  • squidclient_4.6-1+deb10u10+tuxcare.els5_amd64.deb
    sha:e23148d7c07c173b3d37f1ea28ce4d27ab5b1afe
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.