[CLSA-2026:1784886648] squid: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-07-24 09:51:16 UTC
Description:
- CVE-2026-47729: fix out-of-bounds read in FTP gateway directory-listing parser when a listing entry date is not followed by a filename - CVE-2026-50012: fix heap buffer overflow in cache digest reply handling (peerDigestSwapInMask) by bounding mask data against the declared mask_size
Updated packages:
  • squid-3.5.20-17.0.5.el7_9.99.tuxcare.els7.x86_64.rpm
    sha:7bdd0b8e78840ad31b04b026f428be98b9c541babbea697642500f8c54fa212b
  • squid-migration-script-3.5.20-17.0.5.el7_9.99.tuxcare.els7.x86_64.rpm
    sha:faa0973f08c0674397c3557f4522ca25fc8395a45a57299d10710a75c50508b0
  • squid-sysvinit-3.5.20-17.0.5.el7_9.99.tuxcare.els7.x86_64.rpm
    sha:e64150673ab9c52634bc8eab31ed2845631945892e3019bddc577232e16a442d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.