Release date:
2026-07-22 09:01:49 UTC
Description:
* SECURITY UPDATE: out-of-bounds read in the FTP gateway directory-listing
parser when a TypeA/TypeB listing entry date is not followed by a filename
- debian/patches/CVE-2026-47729.patch: restrict parsing to the input buffer
in ftpListParseParts() by checking for a NUL byte before strchr(w_space)
in src/clients/FtpGateway.cc
- CVE-2026-47729
* SECURITY UPDATE: heap-based buffer overflow in cache digest reply handling
when a peer reply's on-the-wire size exceeds the declared mask_size
- debian/patches/CVE-2026-50012.patch: bound-check mask_offset + size
against mask_size before memcpy() in peerDigestSwapInMask() and abort the
fetch on overflow in src/peer_digest.cc
- CVE-2026-50012
Updated packages:
-
squid_4.6-1+deb10u10+tuxcare.els5_amd64.deb
sha:4423a492ec1eb395a62fb21fd3cb137b34c8af3b
-
squid-cgi_4.6-1+deb10u10+tuxcare.els5_amd64.deb
sha:099653c1d9ec386db0217f10d16c30d4be98a986
-
squid-common_4.6-1+deb10u10+tuxcare.els5_all.deb
sha:7d96106b16a8660a628688dd6f000fb458f8cfc0
-
squid-purge_4.6-1+deb10u10+tuxcare.els5_amd64.deb
sha:8a13807ae59aebce90cc62694245aa1214acf666
-
squid3_4.6-1+deb10u10+tuxcare.els5_all.deb
sha:180bbe62532dc5b35cbfcfe5ca21b602a6a84cf3
-
squidclient_4.6-1+deb10u10+tuxcare.els5_amd64.deb
sha:e23148d7c07c173b3d37f1ea28ce4d27ab5b1afe
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.