[CLSA-2026:1784713205] Fix CVE(s): CVE-2026-47729, CVE-2026-50012
Type:
security
Severity:
Moderate
Release date:
2026-07-22 11:21:53 UTC
Description:
* SECURITY UPDATE: out-of-bounds read in FTP gateway listing parser - debian/patches/CVE-2026-47729.patch: guard against a NUL byte before strchr() in ftpListParseParts, preventing an out-of-bounds read that could disclose memory from unrelated transactions - CVE-2026-47729 * SECURITY UPDATE: heap buffer overflow in cache digest handling - debian/patches/CVE-2026-50012.patch: bound the mask copy in peerDigestSwapInMask so an on-the-wire payload larger than the advertised mask size cannot overflow the heap buffer - CVE-2026-50012
Updated packages:
  • squid_3.5.12-1ubuntu7.17+tuxcare.els14_amd64.deb
    sha:d4ae22858a2f92fa95a9d2f302f1b00cf3387cab
  • squid-cgi_3.5.12-1ubuntu7.17+tuxcare.els14_amd64.deb
    sha:d73a6ca95866560f486a8ddf6858d255b57b95a7
  • squid-common_3.5.12-1ubuntu7.17+tuxcare.els14_all.deb
    sha:b145511094a97d7c7376abeef10301ecefb37b06
  • squid-purge_3.5.12-1ubuntu7.17+tuxcare.els14_amd64.deb
    sha:ab45a58ac11fcb5e6f4b5c6809dda4a44c9e2727
  • squid3_3.5.12-1ubuntu7.17+tuxcare.els14_all.deb
    sha:a1a6c2931047d89a837e2b84de7560e1c4d33829
  • squidclient_3.5.12-1ubuntu7.17+tuxcare.els14_amd64.deb
    sha:8bfec3e370bf6761103814fe24efdf5a50987fbc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.