Release date:
2026-07-22 11:21:53 UTC
Description:
* SECURITY UPDATE: out-of-bounds read in FTP gateway listing parser
- debian/patches/CVE-2026-47729.patch: guard against a NUL byte
before strchr() in ftpListParseParts, preventing an out-of-bounds
read that could disclose memory from unrelated transactions
- CVE-2026-47729
* SECURITY UPDATE: heap buffer overflow in cache digest handling
- debian/patches/CVE-2026-50012.patch: bound the mask copy in
peerDigestSwapInMask so an on-the-wire payload larger than the
advertised mask size cannot overflow the heap buffer
- CVE-2026-50012
Updated packages:
-
squid_3.5.12-1ubuntu7.17+tuxcare.els14_amd64.deb
sha:d4ae22858a2f92fa95a9d2f302f1b00cf3387cab
-
squid-cgi_3.5.12-1ubuntu7.17+tuxcare.els14_amd64.deb
sha:d73a6ca95866560f486a8ddf6858d255b57b95a7
-
squid-common_3.5.12-1ubuntu7.17+tuxcare.els14_all.deb
sha:b145511094a97d7c7376abeef10301ecefb37b06
-
squid-purge_3.5.12-1ubuntu7.17+tuxcare.els14_amd64.deb
sha:ab45a58ac11fcb5e6f4b5c6809dda4a44c9e2727
-
squid3_3.5.12-1ubuntu7.17+tuxcare.els14_all.deb
sha:a1a6c2931047d89a837e2b84de7560e1c4d33829
-
squidclient_3.5.12-1ubuntu7.17+tuxcare.els14_amd64.deb
sha:8bfec3e370bf6761103814fe24efdf5a50987fbc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.