Release date:
2026-07-23 10:04:01 UTC
Description:
* SECURITY UPDATE: out-of-bounds read in FTP gateway listing parser
- debian/patches/CVE-2026-47729.patch: guard against a NUL byte
before strchr() in ftpListParseParts, preventing an out-of-bounds
read that could disclose memory from unrelated transactions
- CVE-2026-47729
* SECURITY UPDATE: heap buffer overflow in cache digest handling
- debian/patches/CVE-2026-50012.patch: bound the mask copy in
peerDigestSwapInMask so an on-the-wire payload larger than the
advertised mask size cannot overflow the heap buffer
- CVE-2026-50012
Updated packages:
-
squid_3.5.27-1ubuntu1.14+tuxcare.els12_amd64.deb
sha:28d09cc9622877c2ae8d6185fe53acdac68ad121
-
squid-cgi_3.5.27-1ubuntu1.14+tuxcare.els12_amd64.deb
sha:66a00f6f42f4c185acae0b5be3e8f7299e121a8c
-
squid-common_3.5.27-1ubuntu1.14+tuxcare.els12_all.deb
sha:5516673a5026c5069525afea5e46d88141963302
-
squid-purge_3.5.27-1ubuntu1.14+tuxcare.els12_amd64.deb
sha:2ab87f5a0b9a9fb51e60afbe673fe2118b3e1268
-
squid3_3.5.27-1ubuntu1.14+tuxcare.els12_all.deb
sha:7cf33608b009bf6e3515671fc16c78abff9a9024
-
squidclient_3.5.27-1ubuntu1.14+tuxcare.els12_amd64.deb
sha:4f624ec47b592ed8ca375ddd398eef6721371a7d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.