[CLSA-2026:1784801011] Fix CVE(s): CVE-2026-47729, CVE-2026-50012
Type:
security
Severity:
Moderate
Release date:
2026-07-23 10:04:01 UTC
Description:
* SECURITY UPDATE: out-of-bounds read in FTP gateway listing parser - debian/patches/CVE-2026-47729.patch: guard against a NUL byte before strchr() in ftpListParseParts, preventing an out-of-bounds read that could disclose memory from unrelated transactions - CVE-2026-47729 * SECURITY UPDATE: heap buffer overflow in cache digest handling - debian/patches/CVE-2026-50012.patch: bound the mask copy in peerDigestSwapInMask so an on-the-wire payload larger than the advertised mask size cannot overflow the heap buffer - CVE-2026-50012
Updated packages:
  • squid_3.5.27-1ubuntu1.14+tuxcare.els12_amd64.deb
    sha:28d09cc9622877c2ae8d6185fe53acdac68ad121
  • squid-cgi_3.5.27-1ubuntu1.14+tuxcare.els12_amd64.deb
    sha:66a00f6f42f4c185acae0b5be3e8f7299e121a8c
  • squid-common_3.5.27-1ubuntu1.14+tuxcare.els12_all.deb
    sha:5516673a5026c5069525afea5e46d88141963302
  • squid-purge_3.5.27-1ubuntu1.14+tuxcare.els12_amd64.deb
    sha:2ab87f5a0b9a9fb51e60afbe673fe2118b3e1268
  • squid3_3.5.27-1ubuntu1.14+tuxcare.els12_all.deb
    sha:7cf33608b009bf6e3515671fc16c78abff9a9024
  • squidclient_3.5.27-1ubuntu1.14+tuxcare.els12_amd64.deb
    sha:4f624ec47b592ed8ca375ddd398eef6721371a7d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.