[CLSA-2026:1784805092] squid: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-07-23 11:11:59 UTC
Description:
- CVE-2026-47729: fix out-of-bounds read in FTP gateway directory-listing parser when a listing entry date is not followed by a filename - CVE-2026-50012: fix heap buffer overflow in cache digest reply handling (peerDigestSwapInMask) by bounding mask data against the declared mask_size
Updated packages:
  • squid-3.5.20-17.0.5.el7_9.99.tuxcare.els7.x86_64.rpm
    sha:badd3d95da0861346fb19f9b052a5b3fad39021b1184d8494f87bfc443edb4ab
  • squid-migration-script-3.5.20-17.0.5.el7_9.99.tuxcare.els7.x86_64.rpm
    sha:b6c403d85cbe25da951a96a0fb82bcd8851321c6c7fbf6df270a94b418605923
  • squid-sysvinit-3.5.20-17.0.5.el7_9.99.tuxcare.els7.x86_64.rpm
    sha:19f431af84d8c63ef29a11add2def5ebe883249a80d0981b8f6acc1c349a0cb0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.