[CLSA-2026:1784805083] squid: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-07-23 11:11:51 UTC
Description:
- CVE-2026-47729: fix out-of-bounds read in FTP gateway directory-listing parser when a listing entry date is not followed by a filename - CVE-2026-50012: fix heap buffer overflow in cache digest reply handling (peerDigestSwapInMask) by bounding mask data against the declared mask_size
Updated packages:
  • squid-3.5.20-17.0.5.el7_9.99.tuxcare.els7.x86_64.rpm
    sha:752499fda21cafd97332f58ad720b12b007c15562a73133164d60811c773b00d
  • squid-migration-script-3.5.20-17.0.5.el7_9.99.tuxcare.els7.x86_64.rpm
    sha:87131d9c9bec7dd0ea3a9a22f31acd5149114cbba8cc7f3d481800955b3c2c1c
  • squid-sysvinit-3.5.20-17.0.5.el7_9.99.tuxcare.els7.x86_64.rpm
    sha:fe60da3d17f65acf7ac2a592b8d38e641dbb116ca2a59375a601b9b6c6769f05
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.