[CLSA-2026:1784716497] Fix CVE(s): CVE-2026-47729, CVE-2026-50012
Type:
security
Severity:
Moderate
Release date:
2026-07-22 10:35:24 UTC
Description:
* SECURITY UPDATE: out-of-bounds read in FTP gateway directory-listing parser - debian/patches/CVE-2026-47729.patch: guard the whitespace-skipping strchr(w_space, *copyFrom) checks in ftpListParseParts() with a '*copyFrom &&' short-circuit so a listing date that is not followed by a filename cannot advance parsing past the input buffer - CVE-2026-47729 * SECURITY UPDATE: heap buffer overflow in cache digest reply handling - debian/patches/CVE-2026-50012.patch: bounds-check the received mask data size against the declared mask_size before the memcpy in peerDigestSwapInMask(), aborting the digest fetch when the on-the-wire size is larger than the mask - CVE-2026-50012
Updated packages:
  • squid_4.10-1ubuntu1.13+tuxcare.els5_amd64.deb
    sha:ff28f6d44bcb617c79cf67ec9a95a52e46266bd9
  • squid-cgi_4.10-1ubuntu1.13+tuxcare.els5_amd64.deb
    sha:6aab75f102c9a442b8a8d4caff727381bdc7885a
  • squid-common_4.10-1ubuntu1.13+tuxcare.els5_all.deb
    sha:ed08628e8ebfe763c79776f99266bd9fd5fe68b6
  • squid-purge_4.10-1ubuntu1.13+tuxcare.els5_amd64.deb
    sha:18435c86447030de37746971b8b2b59b44e84cc1
  • squidclient_4.10-1ubuntu1.13+tuxcare.els5_amd64.deb
    sha:66aa597aa66d60949c4c985f83fa1facd9abdb1c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.