[CLSA-2026:1786353802] squid: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-08-13 12:47:28 UTC
Description:
- CVE-2026-47729: fix out-of-bounds read in FTP gateway directory-listing parser when a listing entry date is not followed by a filename - CVE-2026-50012: fix heap buffer overflow in cache digest reply handling (peerDigestSwapInMask) by bounding mask data against the declared mask_size
Updated packages:
  • squid-3.5.20-17.0.5.el7_9.99.tuxcare.els7.x86_64.rpm
    sha:8180f4689eb38198054db901e9a13128bb840c2b65ca593b257a7d35cad3c38a
  • squid-migration-script-3.5.20-17.0.5.el7_9.99.tuxcare.els7.x86_64.rpm
    sha:e7455d1e2165e34c2c2852b7cb4825d1f13e335f84db420181f1c37e6ffcc554
  • squid-sysvinit-3.5.20-17.0.5.el7_9.99.tuxcare.els7.x86_64.rpm
    sha:b5ff00866f052bcd744153bca562d58911fd251efde6ceab268ff1913ca7af3e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.