diff mbox series

[meta-networking,scarthgap,4/7] squid: patch CVE-2026-47729

Message ID 20261009164203.1744134-4-peter.marko@siemens.com
State New
Headers show
Series [meta-networking,scarthgap,1/7] squid: patch CVE-2026-33526 | expand

Commit Message

Peter Marko Oct. 9, 2026, 4:42 p.m. UTC
From: Peter Marko <peter.marko@siemens.com>

Pick SQUID-2026:4 patch per [1].

[1] https://github.com/squid-cache/squid/security/advisories/GHSA-8c37-pxjq-qwrg

Signed-off-by: Peter Marko <peter.marko@siemens.com>
---
 .../squid/files/CVE-2026-47729.patch          | 51 +++++++++++++++++++
 .../recipes-daemons/squid/squid_6.14.bb       |  1 +
 2 files changed, 52 insertions(+)
 create mode 100644 meta-networking/recipes-daemons/squid/files/CVE-2026-47729.patch
diff mbox series

Patch

diff --git a/meta-networking/recipes-daemons/squid/files/CVE-2026-47729.patch b/meta-networking/recipes-daemons/squid/files/CVE-2026-47729.patch
new file mode 100644
index 0000000000..b250d8fbab
--- /dev/null
+++ b/meta-networking/recipes-daemons/squid/files/CVE-2026-47729.patch
@@ -0,0 +1,51 @@ 
+From 865a131c7d557e68c965043d98c2eccae26deef8 Mon Sep 17 00:00:00 2001
+From: squidadm <squidadm@users.noreply.github.com>
+Date: Sun, 17 May 2026 18:04:47 +1200
+Subject: [PATCH] Improve parsing of certain FTP directory listing formats
+ (#2408) (#2409)
+
+This surgical fix restricts parsing to the input buffer when the listing
+entry date in "TypeA" or "TypeB" formats is not followed by a filename.
+It does not improve rendering of listings with missing filenames or the
+overall quality of FTP listing parsing code.
+
+C strchr() always returns a non-nil pointer when given a NUL character,
+so its callers must be careful not to supply a NUL character if a
+"natural" one-of-the-regular-c-string-characters membership test is
+required.
+
+The bug was probably introduced in 1997 commit 3fdadc70 and then
+duplicated in 2017 commit 3d872090.
+
+Co-authored-by: Alex Rousskov <rousskov@measurement-factory.com>
+Co-authored-by: Amos Jeffries <yadij@users.noreply.github.com>
+
+CVE: CVE-2026-47729
+Upstream-Status: Backport [https://github.com/squid-cache/squid/commit/865a131c7d557e68c965043d98c2eccae26deef8]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/clients/FtpGateway.cc | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/src/clients/FtpGateway.cc b/src/clients/FtpGateway.cc
+index 164fd0e49..e04bb603d 100644
+--- a/src/clients/FtpGateway.cc
++++ b/src/clients/FtpGateway.cc
+@@ -622,7 +622,7 @@ ftpListParseParts(const char *buf, struct Ftp::GatewayFlags flags)
+             // point after tokens[i+2] :
+             copyFrom = buf + tokens[i + 2].pos + strlen(tokens[i + 2].token);
+             if (flags.skip_whitespace) {
+-                while (strchr(w_space, *copyFrom))
++                while (*copyFrom && strchr(w_space, *copyFrom))
+                     ++copyFrom;
+             } else {
+                 /* Handle the following four formats:
+@@ -633,7 +633,7 @@ ftpListParseParts(const char *buf, struct Ftp::GatewayFlags flags)
+                  * Assuming a single space between date and filename
+                  * suggested by:  Nathan.Bailey@cc.monash.edu.au and
+                  * Mike Battersby <mike@starbug.bofh.asn.au> */
+-                if (strchr(w_space, *copyFrom))
++                if (*copyFrom && strchr(w_space, *copyFrom))
+                     ++copyFrom;
+             }
+ 
diff --git a/meta-networking/recipes-daemons/squid/squid_6.14.bb b/meta-networking/recipes-daemons/squid/squid_6.14.bb
index 5552cbabcd..e244b97b5c 100644
--- a/meta-networking/recipes-daemons/squid/squid_6.14.bb
+++ b/meta-networking/recipes-daemons/squid/squid_6.14.bb
@@ -25,6 +25,7 @@  SRC_URI = "https://github.com/squid-cache/${BPN}/releases/download/SQUID_${PV_U}
            file://CVE-2026-33526.patch \
            file://CVE-2026-33515.patch \
            file://CVE-2026-32748.patch \
+           file://CVE-2026-47729.patch \
            "
 
 SRC_URI[sha256sum] = "9eafe06f58a199b918e79d33d8aa03afb9ae0c11d18974dca0b44c2669cab6dd"