From patchwork Fri Oct 9 16:41:57 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Marko X-Patchwork-Id: 100252 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 97851CA601E for ; Fri, 9 Oct 2026 16:42:37 +0000 (UTC) Received: from mta-65-227.siemens.flowmailer.net (mta-65-227.siemens.flowmailer.net [185.136.65.227]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.93.1791564147824598224 for ; Fri, 09 Oct 2026 09:42:29 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=peter.marko@siemens.com header.s=fm1 header.b=u/qM+60Z; spf=pass (domain: rts-flowmailer.siemens.com, ip: 185.136.65.227, mailfrom: fm-256628-2026100916422467e6fdd90a00020788-qkzzfu@rts-flowmailer.siemens.com) Received: by mta-65-227.siemens.flowmailer.net with ESMTPSA id 2026100916422467e6fdd90a00020788 for ; Fri, 09 Oct 2026 18:42:24 +0200 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=fm1; d=siemens.com; i=peter.marko@siemens.com; h=Date:From:Subject:To:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding:Cc; bh=+pnJfylU2GSAk06Z0vYYADie1beFliYwmGM17mcfc7w=; b=u/qM+60ZE/FXXx06HaGF2P/bZiMnnL7JTU4wfYcreHdvtti1u2qdyuC6GvrMxq9CQ5o3ei cTA7N1WBFH7IhKlAuiRmtas+GvjErb/nVHZ/lJhUvWOAa/h84DNhEhjBY+DT+JQjQLRFF6uR ul+E+dBybzkQqIKRavQ+RJ1mMUdea1byRf1BvHwdroij8vU0KtRR1SlkdLNoxQbvoN6+N4T/ BffY5goshGU+Q/Y1uu169QTS8Nm9PDWfoFHA/LREbF19rA6AueAslvUQGGEyXJhyv6egwUhH q6sGNtWJufOZTdZESNe/r0P6talZGYp7AomVJB35oCluupyVa9I8b9cQ==; From: Peter Marko To: openembedded-devel@lists.openembedded.org Cc: Peter Marko Subject: [meta-networking][scarthgap][PATCH 1/7] squid: patch CVE-2026-33526 Date: Fri, 9 Oct 2026 18:41:57 +0200 Message-ID: <20261009164203.1744134-1-peter.marko@siemens.com> MIME-Version: 1.0 X-Flowmailer-Platform: Siemens Feedback-ID: 519:519-256628:519-21489:flowmailer List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 09 Oct 2026 16:42:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130697 From: Peter Marko Pick SQUID-2026:1 patch per [1]. [1] https://github.com/squid-cache/squid/security/advisories/GHSA-hpfx-h48q-gvwg Signed-off-by: Peter Marko --- .../squid/files/CVE-2026-33526.patch | 35 +++++++++++++++++++ .../recipes-daemons/squid/squid_6.14.bb | 1 + 2 files changed, 36 insertions(+) create mode 100644 meta-networking/recipes-daemons/squid/files/CVE-2026-33526.patch diff --git a/meta-networking/recipes-daemons/squid/files/CVE-2026-33526.patch b/meta-networking/recipes-daemons/squid/files/CVE-2026-33526.patch new file mode 100644 index 0000000000..beeb07c339 --- /dev/null +++ b/meta-networking/recipes-daemons/squid/files/CVE-2026-33526.patch @@ -0,0 +1,35 @@ +From 8a7d42f9d44befb8fcbbb619505587c8de6a1e91 Mon Sep 17 00:00:00 2001 +From: Joshua Rogers +Date: Tue, 10 Feb 2026 19:58:49 +0000 +Subject: [PATCH] Do not escape malformed URI twice when sending ICP errors + (#2374) + +In this context, escaping escaped URI always produces incorrect URI +because `%` character in the escaped URI gets escaped again. Feeding the +result of the first rfc1738_escape() call to the second call is also +dangerously wrong because the result of the first call gets invalidated +during the second call. + +No other cases of such "chained" rfc1738_escape() calls were found. + +Broken since 2002 commit e6ccf245. + +CVE: CVE-2026-33526 +Upstream-Status: Backport [https://github.com/squid-cache/squid/commit/8a7d42f9d44befb8fcbbb619505587c8de6a1e91] +Signed-off-by: Peter Marko +--- + src/icp_v2.cc | 1 - + 1 file changed, 1 deletion(-) + +diff --git a/src/icp_v2.cc b/src/icp_v2.cc +index 2a4ced3bf..25f7b71d2 100644 +--- a/src/icp_v2.cc ++++ b/src/icp_v2.cc +@@ -457,7 +457,6 @@ HttpRequest * + icpGetRequest(char *url, int reqnum, int fd, Ip::Address &from) + { + if (strpbrk(url, w_space)) { +- url = rfc1738_escape(url); + icpCreateAndSend(ICP_ERR, 0, rfc1738_escape(url), reqnum, 0, fd, from, nullptr); + return nullptr; + } diff --git a/meta-networking/recipes-daemons/squid/squid_6.14.bb b/meta-networking/recipes-daemons/squid/squid_6.14.bb index fc5b827da2..965704920b 100644 --- a/meta-networking/recipes-daemons/squid/squid_6.14.bb +++ b/meta-networking/recipes-daemons/squid/squid_6.14.bb @@ -22,6 +22,7 @@ SRC_URI = "https://github.com/squid-cache/${BPN}/releases/download/SQUID_${PV_U} file://squid.nm \ file://CVE-2025-59362.patch \ file://CVE-2025-62168.patch \ + file://CVE-2026-33526.patch \ " SRC_URI[sha256sum] = "9eafe06f58a199b918e79d33d8aa03afb9ae0c11d18974dca0b44c2669cab6dd" From patchwork Fri Oct 9 16:41:58 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Marko X-Patchwork-Id: 100253 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C7406CA601E for ; Fri, 9 Oct 2026 16:42:47 +0000 (UTC) Received: from mta-65-227.siemens.flowmailer.net (mta-65-227.siemens.flowmailer.net [185.136.65.227]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.112.1791564162033343734 for ; Fri, 09 Oct 2026 09:42:42 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=peter.marko@siemens.com header.s=fm1 header.b=lJYjOpR+; spf=pass (domain: rts-flowmailer.siemens.com, ip: 185.136.65.227, mailfrom: fm-256628-202610091642392cfb1cb60d0002074b-ky9hg_@rts-flowmailer.siemens.com) Received: by mta-65-227.siemens.flowmailer.net with ESMTPSA id 202610091642392cfb1cb60d0002074b for ; Fri, 09 Oct 2026 18:42:39 +0200 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=fm1; d=siemens.com; i=peter.marko@siemens.com; h=Date:From:Subject:To:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding:Cc:References:In-Reply-To; bh=JaSMxfzpgmZjucyfhMXoWMvBDYXqOZhYJnxuvIosYzw=; b=lJYjOpR+APKSzpLYlzsxyXbIfTcHgYTQRzoSI4p29Buea3ceLWn79Tb2F88ZxVi2SHpeYl GkaINDwzf6w3QXLcaHY1sThWd1jZCLDfGC3zs6Vv/BKkNpHLEOULVNcKcpu6uMTaQcc74Mvi dlJ4OHDvJxzQrQeKplygENBUX4KJRCuDyVoe+CP3SOQyNRs5YKanvKUGgh87d4hvVnv6R64o fCRiXCXHcMfdM/KCXhGgfw6tZaohcJCzIfYztvKQgbPAikdn6eRXYDbap3S+5D4AvQw34s7C BMQAbZuzIZ7hSqancDov1nEXkmTFrr/qn3gD4/Jk/8dJsdVVa+oa7Gxw==; From: Peter Marko To: openembedded-devel@lists.openembedded.org Cc: Peter Marko Subject: [meta-networking][scarthgap][PATCH 2/7] squid: patch CVE-2026-33515 Date: Fri, 9 Oct 2026 18:41:58 +0200 Message-ID: <20261009164203.1744134-2-peter.marko@siemens.com> In-Reply-To: <20261009164203.1744134-1-peter.marko@siemens.com> References: <20261009164203.1744134-1-peter.marko@siemens.com> MIME-Version: 1.0 X-Flowmailer-Platform: Siemens Feedback-ID: 519:519-256628:519-21489:flowmailer List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 09 Oct 2026 16:42:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130698 From: Peter Marko Pick SQUID-2026:3 patch per [1]. [1] https://github.com/squid-cache/squid/security/advisories/GHSA-84p4-hcx7-jj7c Signed-off-by: Peter Marko --- .../squid/files/CVE-2026-33515.patch | 199 ++++++++++++++++++ .../recipes-daemons/squid/squid_6.14.bb | 1 + 2 files changed, 200 insertions(+) create mode 100644 meta-networking/recipes-daemons/squid/files/CVE-2026-33515.patch diff --git a/meta-networking/recipes-daemons/squid/files/CVE-2026-33515.patch b/meta-networking/recipes-daemons/squid/files/CVE-2026-33515.patch new file mode 100644 index 0000000000..fdf5a7a6e9 --- /dev/null +++ b/meta-networking/recipes-daemons/squid/files/CVE-2026-33515.patch @@ -0,0 +1,199 @@ +From 8138e909d2058d4401e0ad49b583afaec912b165 Mon Sep 17 00:00:00 2001 +From: Joshua Rogers +Date: Thu, 12 Feb 2026 20:28:43 +0000 +Subject: [PATCH] ICP: Fix validation of packet sizes and URLs (#2220) + +Fix handling of malformed ICP queries and replies instead of passing +invalid URL pointer to consumers, leading to out-of-bounds memory reads +and other problems. These fixes affect both ICP v2 and ICP v3 traffic. + +* Reject packets with URLs that are not NUL-terminated. +* Reject packets with URLs containing embedded NULs or trailing garbage. + +The above two restrictions may backfire if popular ICP agents do send +such malformed URLs, and we will need to do more to handle them +correctly, but it is _safe_ to reject them for now. + +Also protect icpHandleUdp() from dereferencing a nil icpOutgoingConn +pointer. It is not clear whether icpHandleUdp() can be exposed to nil +icpOutgoingConn in current code. More work is needed to polish this. + +CVE: CVE-2026-33515 +Upstream-Status: Backport [https://github.com/squid-cache/squid/commit/8138e909d2058d4401e0ad49b583afaec912b165] +Signed-off-by: Peter Marko +--- + src/ICP.h | 8 ++++-- + src/icp_v2.cc | 57 +++++++++++++++++++++++++++++++++++++------ + src/icp_v3.cc | 10 +++++--- + src/tests/stub_icp.cc | 5 ++-- + 4 files changed, 66 insertions(+), 14 deletions(-) + +diff --git a/src/ICP.h b/src/ICP.h +index 10a8e1c67..e9ad8d0ce 100644 +--- a/src/ICP.h ++++ b/src/ICP.h +@@ -89,8 +89,12 @@ extern Comm::ConnectionPointer icpIncomingConn; + extern Comm::ConnectionPointer icpOutgoingConn; + extern Ip::Address theIcpPublicHostID; + ++/// A URI extracted from the given raw packet buffer. ++/// On errors, details the problem and returns nil. ++const char *icpGetUrl(const Ip::Address &from, const char *, const icp_common_t &); ++ + /// \ingroup ServerProtocolICPAPI +-HttpRequest* icpGetRequest(char *url, int reqnum, int fd, Ip::Address &from); ++HttpRequest *icpGetRequest(const char *url, int reqnum, int fd, const Ip::Address &from); + + /// \ingroup ServerProtocolICPAPI + bool icpAccessAllowed(Ip::Address &from, HttpRequest * icp_request); +@@ -102,7 +106,7 @@ void icpCreateAndSend(icp_opcode, int flags, char const *url, int reqnum, int pa + icp_opcode icpGetCommonOpcode(); + + /// \ingroup ServerProtocolICPAPI +-void icpDenyAccess(Ip::Address &from, char *url, int reqnum, int fd); ++void icpDenyAccess(const Ip::Address &from, const char *url, int reqnum, int fd); + + /// \ingroup ServerProtocolICPAPI + PF icpHandleUdp; +diff --git a/src/icp_v2.cc b/src/icp_v2.cc +index 25f7b71d2..312104024 100644 +--- a/src/icp_v2.cc ++++ b/src/icp_v2.cc +@@ -425,7 +425,7 @@ icpCreateAndSend(icp_opcode opcode, int flags, char const *url, int reqnum, int + } + + void +-icpDenyAccess(Ip::Address &from, char *url, int reqnum, int fd) ++icpDenyAccess(const Ip::Address &from, const char * const url, const int reqnum, const int fd) + { + debugs(12, 2, "icpDenyAccess: Access Denied for " << from << " by " << AclMatchedName << "."); + +@@ -453,8 +453,41 @@ icpAccessAllowed(Ip::Address &from, HttpRequest * icp_request) + return checklist.fastCheck().allowed(); + } + ++const char * ++icpGetUrl(const Ip::Address &from, const char * const buf, const icp_common_t &header) ++{ ++ const auto receivedPacketSize = static_cast(header.length); ++ const auto payloadOffset = sizeof(header); ++ ++ // Query payload contains a "Requester Host Address" followed by a URL. ++ // Payload of other ICP packets (with opcode that we recognize) is a URL. ++ const auto urlOffset = payloadOffset + ((header.opcode == ICP_QUERY) ? sizeof(uint32_t) : 0); ++ ++ // A URL field cannot be empty because it includes a terminating NUL char. ++ // Ensure that the packet has at least one URL field byte. ++ if (urlOffset >= receivedPacketSize) { ++ debugs(12, 3, "too small packet from " << from << ": " << urlOffset << " >= " << receivedPacketSize); ++ return nullptr; ++ } ++ ++ // All ICP packets (with opcode that we recognize) _end_ with a URL field. ++ // RFC 2186 requires all URLs to be "Null-Terminated". ++ if (buf[receivedPacketSize - 1] != '\0') { ++ debugs(12, 3, "unterminated URL or trailing garbage from " << from); ++ return nullptr; ++ } ++ ++ const auto url = buf + urlOffset; // a possibly empty c-string ++ if (urlOffset + strlen(url) + 1 != receivedPacketSize) { ++ debugs(12, 3, "URL with an embedded NUL or trailing garbage from " << from); ++ return nullptr; ++ } ++ ++ return url; ++} ++ + HttpRequest * +-icpGetRequest(char *url, int reqnum, int fd, Ip::Address &from) ++icpGetRequest(const char * const url, const int reqnum, const int fd, const Ip::Address &from) + { + if (strpbrk(url, w_space)) { + icpCreateAndSend(ICP_ERR, 0, rfc1738_escape(url), reqnum, 0, fd, from, nullptr); +@@ -471,13 +504,18 @@ icpGetRequest(char *url, int reqnum, int fd, Ip::Address &from) + } + + static void +-doV2Query(int fd, Ip::Address &from, char *buf, icp_common_t header) ++doV2Query(const int fd, Ip::Address &from, const char * const buf, icp_common_t header) + { + int rtt = 0; + int src_rtt = 0; + uint32_t flags = 0; +- /* We have a valid packet */ +- char *url = buf + sizeof(icp_common_t) + sizeof(uint32_t); ++ ++ const auto url = icpGetUrl(from, buf, header); ++ if (!url) { ++ icpCreateAndSend(ICP_ERR, 0, "", header.reqnum, 0, fd, from, nullptr); ++ return; ++ } ++ + HttpRequest *icp_request = icpGetRequest(url, header.reqnum, fd, from); + + if (!icp_request) +@@ -544,7 +582,9 @@ icp_common_t::handleReply(char *buf, Ip::Address &from) + neighbors_do_private_keys = 0; + } + +- char *url = buf + sizeof(icp_common_t); ++ const auto url = icpGetUrl(from, buf, *this); ++ if (!url) ++ return; + debugs(12, 3, "icpHandleIcpV2: " << icp_opcode_str[opcode] << " from " << from << " for '" << url << "'"); + + const cache_key *key = icpGetCacheKey(url, (int) reqnum); +@@ -679,7 +719,10 @@ icpHandleUdp(int sock, void *) + + icp_version = (int) buf[1]; /* cheat! */ + +- if (icpOutgoingConn->local == from) ++ // XXX: The IP equality comparison below ignores port differences but ++ // should not. It also fails to detect loops when `local` is a wildcard ++ // address (e.g., [::]:3130) because `from` address is never a wildcard. ++ if (icpOutgoingConn && icpOutgoingConn->local == from) + // ignore ICP packets which loop back (multicast usually) + debugs(12, 4, "icpHandleUdp: Ignoring UDP packet sent by myself"); + else if (icp_version == ICP_VERSION_2) +diff --git a/src/icp_v3.cc b/src/icp_v3.cc +index c912dd4c0..844768aa0 100644 +--- a/src/icp_v3.cc ++++ b/src/icp_v3.cc +@@ -32,10 +32,14 @@ public: + + /// \ingroup ServerProtocolICPInternal3 + static void +-doV3Query(int fd, Ip::Address &from, char *buf, icp_common_t header) ++doV3Query(int fd, Ip::Address &from, const char * const buf, icp_common_t header) + { +- /* We have a valid packet */ +- char *url = buf + sizeof(icp_common_t) + sizeof(uint32_t); ++ const auto url = icpGetUrl(from, buf, header); ++ if (!url) { ++ icpCreateAndSend(ICP_ERR, 0, "", header.reqnum, 0, fd, from, nullptr); ++ return; ++ } ++ + HttpRequest *icp_request = icpGetRequest(url, header.reqnum, fd, from); + + if (!icp_request) +diff --git a/src/tests/stub_icp.cc b/src/tests/stub_icp.cc +index 44091838b..d148ab66d 100644 +--- a/src/tests/stub_icp.cc ++++ b/src/tests/stub_icp.cc +@@ -29,11 +29,12 @@ Comm::ConnectionPointer icpIncomingConn; + Comm::ConnectionPointer icpOutgoingConn; + Ip::Address theIcpPublicHostID; + +-HttpRequest* icpGetRequest(char *, int, int, Ip::Address &) STUB_RETVAL(nullptr) ++const char *icpGetUrl(const Ip::Address &, const char *, const icp_common_t &) STUB_RETVAL(nullptr) ++HttpRequest* icpGetRequest(const char *, int, int, const Ip::Address &) STUB_RETVAL(nullptr) + bool icpAccessAllowed(Ip::Address &, HttpRequest *) STUB_RETVAL(false) + void icpCreateAndSend(icp_opcode, int, char const *, int, int, int, const Ip::Address &, AccessLogEntryPointer) STUB + icp_opcode icpGetCommonOpcode() STUB_RETVAL(ICP_INVALID) +-void icpDenyAccess(Ip::Address &, char *, int, int) STUB ++void icpDenyAccess(const Ip::Address &, const char *, int, int) STUB + void icpHandleIcpV3(int, Ip::Address &, char *, int) STUB + void icpConnectionShutdown(void) STUB + int icpSetCacheKey(const cache_key *) STUB_RETVAL(0) diff --git a/meta-networking/recipes-daemons/squid/squid_6.14.bb b/meta-networking/recipes-daemons/squid/squid_6.14.bb index 965704920b..5c3bd46b29 100644 --- a/meta-networking/recipes-daemons/squid/squid_6.14.bb +++ b/meta-networking/recipes-daemons/squid/squid_6.14.bb @@ -23,6 +23,7 @@ SRC_URI = "https://github.com/squid-cache/${BPN}/releases/download/SQUID_${PV_U} file://CVE-2025-59362.patch \ file://CVE-2025-62168.patch \ file://CVE-2026-33526.patch \ + file://CVE-2026-33515.patch \ " SRC_URI[sha256sum] = "9eafe06f58a199b918e79d33d8aa03afb9ae0c11d18974dca0b44c2669cab6dd" From patchwork Fri Oct 9 16:41:59 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Marko X-Patchwork-Id: 100254 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 77F14CA601E for ; Fri, 9 Oct 2026 16:42:57 +0000 (UTC) Received: from mta-64-226.siemens.flowmailer.net (mta-64-226.siemens.flowmailer.net [185.136.64.226]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.126.1791564172383685799 for ; Fri, 09 Oct 2026 09:42:52 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=peter.marko@siemens.com header.s=fm1 header.b=Qhxujole; spf=pass (domain: rts-flowmailer.siemens.com, ip: 185.136.64.226, mailfrom: fm-256628-20261009164250c1a3009252000207b7-46of60@rts-flowmailer.siemens.com) Received: by mta-64-226.siemens.flowmailer.net with ESMTPSA id 20261009164250c1a3009252000207b7 for ; Fri, 09 Oct 2026 18:42:50 +0200 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=fm1; d=siemens.com; i=peter.marko@siemens.com; h=Date:From:Subject:To:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding:Cc:References:In-Reply-To; bh=HAgL9xGnLJHSxZ0kNm4mGEm+G/7GVFr32K2OGjLU/iQ=; b=QhxujolenNrR4dtdHJ3aO86t6JsOyvaOlMeUaTyMgWHNXXeXMmaKvYI5E0GX44UHhCJpjj hkuVk4yLYA+N9eqqMTw4vGfA9DJKtqIutDMXubRujwipsGJv+1J4PLhOcnr6+aKwbEIulT9i g6QkbRHeab9PY3nDBRub+RJajNL870EaG5o0WOcSU+ZK11LmOza9365Spv1yo+eUs+LbQ5LM q7hLYxkju3DZncrvyoW75uStC+d56H2pa0ARE3vTVli7e7D7+0Cvhvw3dJURLtR8tFJPAhYv He9kfA3DHrAjd4OlV1jOJ7pTUJFVB/uKMskzUPqdHdSmA0u23uBoCe6A==; From: Peter Marko To: openembedded-devel@lists.openembedded.org Cc: Peter Marko Subject: [meta-networking][scarthgap][PATCH 3/7] squid: patch CVE-2026-32748 Date: Fri, 9 Oct 2026 18:41:59 +0200 Message-ID: <20261009164203.1744134-3-peter.marko@siemens.com> In-Reply-To: <20261009164203.1744134-1-peter.marko@siemens.com> References: <20261009164203.1744134-1-peter.marko@siemens.com> MIME-Version: 1.0 X-Flowmailer-Platform: Siemens Feedback-ID: 519:519-256628:519-21489:flowmailer List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 09 Oct 2026 16:42:57 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130699 From: Peter Marko Pick SQUID-2026:2 patch per [1]. [1] https://github.com/squid-cache/squid/security/advisories/GHSA-f9p7-3jqg-hhvq Signed-off-by: Peter Marko --- .../squid/files/CVE-2026-32748.patch | 182 ++++++++++++++++++ .../recipes-daemons/squid/squid_6.14.bb | 1 + 2 files changed, 183 insertions(+) create mode 100644 meta-networking/recipes-daemons/squid/files/CVE-2026-32748.patch diff --git a/meta-networking/recipes-daemons/squid/files/CVE-2026-32748.patch b/meta-networking/recipes-daemons/squid/files/CVE-2026-32748.patch new file mode 100644 index 0000000000..f492a9f4bb --- /dev/null +++ b/meta-networking/recipes-daemons/squid/files/CVE-2026-32748.patch @@ -0,0 +1,182 @@ +From 703e07d25ca6fa11f52d20bf0bb879e22ab7481b Mon Sep 17 00:00:00 2001 +From: Alex Rousskov +Date: Wed, 18 Feb 2026 21:13:26 +0000 +Subject: [PATCH] ICP: Fix HttpRequest lifetime for ICP v3 queries (#2377) + +ACLFilledChecklist correctly locks and unlocks HttpRequest. Thus, when +given an unlocked request object, an on-stack checklist destroys it. +Upon icpAccessAllowed() return, Squid uses the destroyed request object. + +This bug was probably introduced in 2003 commit 8000a965 that started +automatically unlocking requests in ACLChecklist destructor. However, +the bug did not affect allowed ICP v3 queries until 2007 commit f72fb56b +started _using_ the request object for them. 2005 commit 319bf5a7 fixed +an equivalent ICP v2 bug for denied queries but missed the ICP v3 case. + +The scope, age, and effect of this bug imply that Squid v3+ deployments +receive no ICP v3 queries since 2007 (or earlier). Squid itself does not +send ICP v3 messages, responding with ICP v2 replies to ICP v3 queries. +TODO: Consider dropping ICP v3 support. + +Also moved icpAccessAllowed() inside icpGetRequest() to deduplicate code +and reduce the risk of allowing a request without consulting icp_access. + +CVE: CVE-2026-32748 +Upstream-Status: Backport [https://github.com/squid-cache/squid/commit/703e07d25ca6fa11f52d20bf0bb879e22ab7481b] +Signed-off-by: Peter Marko +--- + src/ICP.h | 5 +---- + src/icp_v2.cc | 33 +++++++++++++++------------------ + src/icp_v3.cc | 10 ++-------- + src/tests/stub_icp.cc | 4 ++-- + 4 files changed, 20 insertions(+), 32 deletions(-) + +diff --git a/src/ICP.h b/src/ICP.h +index e9ad8d0ce..a042d2d74 100644 +--- a/src/ICP.h ++++ b/src/ICP.h +@@ -94,10 +94,7 @@ extern Ip::Address theIcpPublicHostID; + const char *icpGetUrl(const Ip::Address &from, const char *, const icp_common_t &); + + /// \ingroup ServerProtocolICPAPI +-HttpRequest *icpGetRequest(const char *url, int reqnum, int fd, const Ip::Address &from); +- +-/// \ingroup ServerProtocolICPAPI +-bool icpAccessAllowed(Ip::Address &from, HttpRequest * icp_request); ++HttpRequestPointer icpGetRequest(const char *url, int reqnum, int fd, const Ip::Address &from); + + /// \ingroup ServerProtocolICPAPI + void icpCreateAndSend(icp_opcode, int flags, char const *url, int reqnum, int pad, int fd, const Ip::Address &from, AccessLogEntryPointer); +diff --git a/src/icp_v2.cc b/src/icp_v2.cc +index 312104024..33baf9787 100644 +--- a/src/icp_v2.cc ++++ b/src/icp_v2.cc +@@ -440,8 +440,9 @@ icpDenyAccess(const Ip::Address &from, const char * const url, const int reqnum, + } + } + +-bool +-icpAccessAllowed(Ip::Address &from, HttpRequest * icp_request) ++/// icpGetRequest() helper that determines whether squid.conf allows the given ICP query ++static bool ++icpAccessAllowed(const Ip::Address &from, HttpRequest * icp_request) + { + /* absent any explicit rules, we deny all */ + if (!Config.accessList.icp) +@@ -486,7 +487,7 @@ icpGetUrl(const Ip::Address &from, const char * const buf, const icp_common_t &h + return url; + } + +-HttpRequest * ++HttpRequest::Pointer + icpGetRequest(const char * const url, const int reqnum, const int fd, const Ip::Address &from) + { + if (strpbrk(url, w_space)) { +@@ -495,12 +496,17 @@ icpGetRequest(const char * const url, const int reqnum, const int fd, const Ip:: + } + + const auto mx = MasterXaction::MakePortless(); +- auto *result = HttpRequest::FromUrlXXX(url, mx); +- if (!result) +- icpCreateAndSend(ICP_ERR, 0, url, reqnum, 0, fd, from, nullptr); ++ if (const HttpRequest::Pointer request = HttpRequest::FromUrlXXX(url, mx)) { ++ if (!icpAccessAllowed(from, request.getRaw())) { ++ icpDenyAccess(from, url, reqnum, fd); ++ return nullptr; ++ } + +- return result; ++ return request; ++ } + ++ icpCreateAndSend(ICP_ERR, 0, url, reqnum, 0, fd, from, nullptr); ++ return nullptr; + } + + static void +@@ -516,18 +522,11 @@ doV2Query(const int fd, Ip::Address &from, const char * const buf, icp_common_t + return; + } + +- HttpRequest *icp_request = icpGetRequest(url, header.reqnum, fd, from); ++ const auto icp_request = icpGetRequest(url, header.reqnum, fd, from); + + if (!icp_request) + return; + +- HTTPMSGLOCK(icp_request); +- +- if (!icpAccessAllowed(from, icp_request)) { +- icpDenyAccess(from, url, header.reqnum, fd); +- HTTPMSGUNLOCK(icp_request); +- return; +- } + #if USE_ICMP + if (header.flags & ICP_FLAG_SRC_RTT) { + rtt = netdbHostRtt(icp_request->url.host()); +@@ -540,7 +539,7 @@ doV2Query(const int fd, Ip::Address &from, const char * const buf, icp_common_t + #endif /* USE_ICMP */ + + /* The peer is allowed to use this cache */ +- ICP2State state(header, icp_request); ++ ICP2State state(header, icp_request.getRaw()); + state.fd = fd; + state.from = from; + state.url = xstrdup(url); +@@ -569,8 +568,6 @@ doV2Query(const int fd, Ip::Address &from, const char * const buf, icp_common_t + } + + icpCreateAndSend(codeToSend, flags, url, header.reqnum, src_rtt, fd, from, state.al); +- +- HTTPMSGUNLOCK(icp_request); + } + + void +diff --git a/src/icp_v3.cc b/src/icp_v3.cc +index 844768aa0..3864b0b74 100644 +--- a/src/icp_v3.cc ++++ b/src/icp_v3.cc +@@ -40,19 +40,13 @@ doV3Query(int fd, Ip::Address &from, const char * const buf, icp_common_t header + return; + } + +- HttpRequest *icp_request = icpGetRequest(url, header.reqnum, fd, from); ++ const auto icp_request = icpGetRequest(url, header.reqnum, fd, from); + + if (!icp_request) + return; + +- if (!icpAccessAllowed(from, icp_request)) { +- icpDenyAccess (from, url, header.reqnum, fd); +- delete icp_request; +- return; +- } +- + /* The peer is allowed to use this cache */ +- ICP3State state(header, icp_request); ++ ICP3State state(header, icp_request.getRaw()); + state.fd = fd; + state.from = from; + state.url = xstrdup(url); +diff --git a/src/tests/stub_icp.cc b/src/tests/stub_icp.cc +index d148ab66d..4c9037495 100644 +--- a/src/tests/stub_icp.cc ++++ b/src/tests/stub_icp.cc +@@ -9,6 +9,7 @@ + #include "squid.h" + #include "AccessLogEntry.h" + #include "comm/Connection.h" ++#include "HttpRequest.h" + #include "ICP.h" + + #define STUB_API "icp_*.cc" +@@ -30,8 +31,7 @@ Comm::ConnectionPointer icpOutgoingConn; + Ip::Address theIcpPublicHostID; + + const char *icpGetUrl(const Ip::Address &, const char *, const icp_common_t &) STUB_RETVAL(nullptr) +-HttpRequest* icpGetRequest(const char *, int, int, const Ip::Address &) STUB_RETVAL(nullptr) +-bool icpAccessAllowed(Ip::Address &, HttpRequest *) STUB_RETVAL(false) ++HttpRequest::Pointer icpGetRequest(const char *, int, int, const Ip::Address &) STUB_RETVAL(nullptr) + void icpCreateAndSend(icp_opcode, int, char const *, int, int, int, const Ip::Address &, AccessLogEntryPointer) STUB + icp_opcode icpGetCommonOpcode() STUB_RETVAL(ICP_INVALID) + void icpDenyAccess(const Ip::Address &, const char *, int, int) STUB diff --git a/meta-networking/recipes-daemons/squid/squid_6.14.bb b/meta-networking/recipes-daemons/squid/squid_6.14.bb index 5c3bd46b29..5552cbabcd 100644 --- a/meta-networking/recipes-daemons/squid/squid_6.14.bb +++ b/meta-networking/recipes-daemons/squid/squid_6.14.bb @@ -24,6 +24,7 @@ SRC_URI = "https://github.com/squid-cache/${BPN}/releases/download/SQUID_${PV_U} file://CVE-2025-62168.patch \ file://CVE-2026-33526.patch \ file://CVE-2026-33515.patch \ + file://CVE-2026-32748.patch \ " SRC_URI[sha256sum] = "9eafe06f58a199b918e79d33d8aa03afb9ae0c11d18974dca0b44c2669cab6dd" From patchwork Fri Oct 9 16:42:00 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Marko X-Patchwork-Id: 100255 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7C1DDCA601E for ; Fri, 9 Oct 2026 16:43:07 +0000 (UTC) Received: from mta-65-226.siemens.flowmailer.net (mta-65-226.siemens.flowmailer.net [185.136.65.226]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.119.1791564182880262679 for ; Fri, 09 Oct 2026 09:43:03 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=peter.marko@siemens.com header.s=fm1 header.b=blbxDiBi; spf=pass (domain: rts-flowmailer.siemens.com, ip: 185.136.65.226, mailfrom: fm-256628-202610091643001bc27febdf000207a0-nlchnl@rts-flowmailer.siemens.com) Received: by mta-65-226.siemens.flowmailer.net with ESMTPSA id 202610091643001bc27febdf000207a0 for ; Fri, 09 Oct 2026 18:43:01 +0200 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=fm1; d=siemens.com; i=peter.marko@siemens.com; h=Date:From:Subject:To:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding:Cc:References:In-Reply-To; bh=/e/04Gbe9w1FULLdar4TeKA8qS2EknopubBHTSjKAnM=; b=blbxDiBiJwHocXNYL1y3n6Rf4WRcynhMHFbGwEhkBs3t4x9E2fySYH5yMBMJUezYZDXZpg PAjfaSxmUXndJfY49wlebsReazTsZ83TkN98vxdhvpctbPyvzrl3lH3SBUaKOGxOYrTxqG5i iTO4rXpskIuIXbpA31LyEXllcV4k9t+lijj0VinVuT2XG2Oi3/FsH+CdQxaNWoHUIEzW3O0e 7egT9YC7Rem7/+re6DI9HX+1A5w97wOtA0VII+/CKsPzf9X+taV6l/StQWihXSZuCNo5hZGd oh8Zrs8bw28Cmd04hEkDcGVZBLwVRJsdbforZGwlzSffvAiEWrjmbPAg==; From: Peter Marko To: openembedded-devel@lists.openembedded.org Cc: Peter Marko Subject: [meta-networking][scarthgap][PATCH 4/7] squid: patch CVE-2026-47729 Date: Fri, 9 Oct 2026 18:42:00 +0200 Message-ID: <20261009164203.1744134-4-peter.marko@siemens.com> In-Reply-To: <20261009164203.1744134-1-peter.marko@siemens.com> References: <20261009164203.1744134-1-peter.marko@siemens.com> MIME-Version: 1.0 X-Flowmailer-Platform: Siemens Feedback-ID: 519:519-256628:519-21489:flowmailer List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 09 Oct 2026 16:43:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130700 From: Peter Marko Pick SQUID-2026:4 patch per [1]. [1] https://github.com/squid-cache/squid/security/advisories/GHSA-8c37-pxjq-qwrg Signed-off-by: Peter Marko --- .../squid/files/CVE-2026-47729.patch | 51 +++++++++++++++++++ .../recipes-daemons/squid/squid_6.14.bb | 1 + 2 files changed, 52 insertions(+) create mode 100644 meta-networking/recipes-daemons/squid/files/CVE-2026-47729.patch diff --git a/meta-networking/recipes-daemons/squid/files/CVE-2026-47729.patch b/meta-networking/recipes-daemons/squid/files/CVE-2026-47729.patch new file mode 100644 index 0000000000..b250d8fbab --- /dev/null +++ b/meta-networking/recipes-daemons/squid/files/CVE-2026-47729.patch @@ -0,0 +1,51 @@ +From 865a131c7d557e68c965043d98c2eccae26deef8 Mon Sep 17 00:00:00 2001 +From: squidadm +Date: Sun, 17 May 2026 18:04:47 +1200 +Subject: [PATCH] Improve parsing of certain FTP directory listing formats + (#2408) (#2409) + +This surgical fix restricts parsing to the input buffer when the listing +entry date in "TypeA" or "TypeB" formats is not followed by a filename. +It does not improve rendering of listings with missing filenames or the +overall quality of FTP listing parsing code. + +C strchr() always returns a non-nil pointer when given a NUL character, +so its callers must be careful not to supply a NUL character if a +"natural" one-of-the-regular-c-string-characters membership test is +required. + +The bug was probably introduced in 1997 commit 3fdadc70 and then +duplicated in 2017 commit 3d872090. + +Co-authored-by: Alex Rousskov +Co-authored-by: Amos Jeffries + +CVE: CVE-2026-47729 +Upstream-Status: Backport [https://github.com/squid-cache/squid/commit/865a131c7d557e68c965043d98c2eccae26deef8] +Signed-off-by: Peter Marko +--- + src/clients/FtpGateway.cc | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/src/clients/FtpGateway.cc b/src/clients/FtpGateway.cc +index 164fd0e49..e04bb603d 100644 +--- a/src/clients/FtpGateway.cc ++++ b/src/clients/FtpGateway.cc +@@ -622,7 +622,7 @@ ftpListParseParts(const char *buf, struct Ftp::GatewayFlags flags) + // point after tokens[i+2] : + copyFrom = buf + tokens[i + 2].pos + strlen(tokens[i + 2].token); + if (flags.skip_whitespace) { +- while (strchr(w_space, *copyFrom)) ++ while (*copyFrom && strchr(w_space, *copyFrom)) + ++copyFrom; + } else { + /* Handle the following four formats: +@@ -633,7 +633,7 @@ ftpListParseParts(const char *buf, struct Ftp::GatewayFlags flags) + * Assuming a single space between date and filename + * suggested by: Nathan.Bailey@cc.monash.edu.au and + * Mike Battersby */ +- if (strchr(w_space, *copyFrom)) ++ if (*copyFrom && strchr(w_space, *copyFrom)) + ++copyFrom; + } + diff --git a/meta-networking/recipes-daemons/squid/squid_6.14.bb b/meta-networking/recipes-daemons/squid/squid_6.14.bb index 5552cbabcd..e244b97b5c 100644 --- a/meta-networking/recipes-daemons/squid/squid_6.14.bb +++ b/meta-networking/recipes-daemons/squid/squid_6.14.bb @@ -25,6 +25,7 @@ SRC_URI = "https://github.com/squid-cache/${BPN}/releases/download/SQUID_${PV_U} file://CVE-2026-33526.patch \ file://CVE-2026-33515.patch \ file://CVE-2026-32748.patch \ + file://CVE-2026-47729.patch \ " SRC_URI[sha256sum] = "9eafe06f58a199b918e79d33d8aa03afb9ae0c11d18974dca0b44c2669cab6dd" From patchwork Fri Oct 9 16:42:01 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Marko X-Patchwork-Id: 100256 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7C235CA601D for ; Fri, 9 Oct 2026 16:43:17 +0000 (UTC) Received: from mta-65-227.siemens.flowmailer.net (mta-65-227.siemens.flowmailer.net [185.136.65.227]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.127.1791564192835375225 for ; Fri, 09 Oct 2026 09:43:13 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=peter.marko@siemens.com header.s=fm1 header.b=NYL+dWe0; spf=pass (domain: rts-flowmailer.siemens.com, ip: 185.136.65.227, mailfrom: fm-256628-20261009164311c6c309556700020709-nn5izn@rts-flowmailer.siemens.com) Received: by mta-65-227.siemens.flowmailer.net with ESMTPSA id 20261009164311c6c309556700020709 for ; Fri, 09 Oct 2026 18:43:11 +0200 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=fm1; d=siemens.com; i=peter.marko@siemens.com; h=Date:From:Subject:To:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding:Cc:References:In-Reply-To; bh=w0uzgh9RmqgXXUx6pg8iK1vkPr48Rxw1l1wULCQY1U0=; b=NYL+dWe07entnVAXUllzVWhkfcPGe3otv65EMaQAftPD/paPfY/h1VEJFs2nWJmgPDaEv/ Fx6o4SLzSv6+qTD0Ov7LYTGbnNKkdJ+9nGtnTLa1DlKgspjnREmLXg6x6FjOK69p9rHOGE6a Rhi8+bgP8WCHdQTu2yqm9YxLbq4p6/0sqB8xqxCI/nRfkSlH4QEDBGUIqhUD11ifUpdHsHh6 511PE5tPCTzYm6qd6RlcN5VgzQ1eGXGSQLaosOY40cQU7FNzOq1Vauboq4c1q20i8gpbHd1X AraqTxdAI6dJWMQ2WesDS/vAUiuNpVKYkWejcD3Y7o7IUpVY2zluSngg==; From: Peter Marko To: openembedded-devel@lists.openembedded.org Cc: Peter Marko Subject: [meta-networking][scarthgap][PATCH 5/7] squid: patch CVE-2026-50012 Date: Fri, 9 Oct 2026 18:42:01 +0200 Message-ID: <20261009164203.1744134-5-peter.marko@siemens.com> In-Reply-To: <20261009164203.1744134-1-peter.marko@siemens.com> References: <20261009164203.1744134-1-peter.marko@siemens.com> MIME-Version: 1.0 X-Flowmailer-Platform: Siemens Feedback-ID: 519:519-256628:519-21489:flowmailer List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 09 Oct 2026 16:43:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130701 From: Peter Marko Pick SQUID-2026:5 patch per [1]. Also add compilation error fix per [2]. [1] https://github.com/squid-cache/squid/security/advisories/GHSA-5vmx-9x64-9284 [2] https://security-tracker.debian.org/tracker/CVE-2026-50012 Signed-off-by: Peter Marko --- .../squid/files/CVE-2026-50012-01.patch | 34 +++++++++++++++++++ .../squid/files/CVE-2026-50012-02.patch | 31 +++++++++++++++++ .../recipes-daemons/squid/squid_6.14.bb | 2 ++ 3 files changed, 67 insertions(+) create mode 100644 meta-networking/recipes-daemons/squid/files/CVE-2026-50012-01.patch create mode 100644 meta-networking/recipes-daemons/squid/files/CVE-2026-50012-02.patch diff --git a/meta-networking/recipes-daemons/squid/files/CVE-2026-50012-01.patch b/meta-networking/recipes-daemons/squid/files/CVE-2026-50012-01.patch new file mode 100644 index 0000000000..bd32f57cc4 --- /dev/null +++ b/meta-networking/recipes-daemons/squid/files/CVE-2026-50012-01.patch @@ -0,0 +1,34 @@ +From 19fcfe922717c8b255270c032dcde4071c003bcd Mon Sep 17 00:00:00 2001 +From: Francesco Chemolli <5175948+kinkie@users.noreply.github.com> +Date: Sat, 30 May 2026 10:16:33 +0000 +Subject: [PATCH] Harden peerDigestSwapInMask against invalid cache digest + reply (#2423) + +A cache_digest on-the-wire size may be bigger than the +mask_size declared in the digest itself. + +Ignore the digest in case this happens. + +CVE: CVE-2026-50012 +Upstream-Status: Backport [https://github.com/squid-cache/squid/commit/19fcfe922717c8b255270c032dcde4071c003bcd] +Signed-off-by: Peter Marko +--- + src/peer_digest.cc | 5 +++++ + 1 file changed, 5 insertions(+) + +diff --git a/src/peer_digest.cc b/src/peer_digest.cc +index 741090574..53dac203e 100644 +--- a/src/peer_digest.cc ++++ b/src/peer_digest.cc +@@ -622,6 +622,11 @@ peerDigestSwapInMask(void *data, char *buf, ssize_t size) + * NOTENOTENOTENOTENOTE: buf doesn't point to pd->cd->mask anymore! + * we need to do the copy ourselves! + */ ++ Assure(size >= 0); ++ if (fetch->mask_offset + size > static_cast(pd->cd->mask_size)) { ++ finishAndDeleteFetch(fetch, "peer digest mask data too large", true); ++ return -1; ++ } + memcpy(pd->cd->mask + fetch->mask_offset, buf, size); + + /* NOTE! buf points to the middle of pd->cd->mask! */ diff --git a/meta-networking/recipes-daemons/squid/files/CVE-2026-50012-02.patch b/meta-networking/recipes-daemons/squid/files/CVE-2026-50012-02.patch new file mode 100644 index 0000000000..919c6b8314 --- /dev/null +++ b/meta-networking/recipes-daemons/squid/files/CVE-2026-50012-02.patch @@ -0,0 +1,31 @@ +From c9c9a06be6fb21f400014dcb0ec7e6d573167a5d Mon Sep 17 00:00:00 2001 +From: Francesco Chemolli <5175948+kinkie@users.noreply.github.com> +Date: Tue, 2 Jun 2026 20:53:07 +0000 +Subject: [PATCH] Fix -Wsign-compare on arm32 (#2432) + +Due to ssize_t differences on 32/64 bit platforms, changes +to peerDigestSwapInMask in commit 556b91a8a7 cause +signedness comparison errors. +Refactor to be safe both on 32- and 64-bit platforms + +CVE: CVE-2026-50012 +Upstream-Status: Backport [https://github.com/squid-cache/squid/commit/c9c9a06be6fb21f400014dcb0ec7e6d573167a5d] +Signed-off-by: Peter Marko +--- + src/peer_digest.cc | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +diff --git a/src/peer_digest.cc b/src/peer_digest.cc +index 53dac203e..2ad08043e 100644 +--- a/src/peer_digest.cc ++++ b/src/peer_digest.cc +@@ -623,7 +623,8 @@ peerDigestSwapInMask(void *data, char *buf, ssize_t size) + * we need to do the copy ourselves! + */ + Assure(size >= 0); +- if (fetch->mask_offset + size > static_cast(pd->cd->mask_size)) { ++ Assure(pd->cd->mask_size >= fetch->mask_offset); ++ if (static_cast(size) > pd->cd->mask_size - fetch->mask_offset) { + finishAndDeleteFetch(fetch, "peer digest mask data too large", true); + return -1; + } diff --git a/meta-networking/recipes-daemons/squid/squid_6.14.bb b/meta-networking/recipes-daemons/squid/squid_6.14.bb index e244b97b5c..ddaa4e48ac 100644 --- a/meta-networking/recipes-daemons/squid/squid_6.14.bb +++ b/meta-networking/recipes-daemons/squid/squid_6.14.bb @@ -26,6 +26,8 @@ SRC_URI = "https://github.com/squid-cache/${BPN}/releases/download/SQUID_${PV_U} file://CVE-2026-33515.patch \ file://CVE-2026-32748.patch \ file://CVE-2026-47729.patch \ + file://CVE-2026-50012-01.patch \ + file://CVE-2026-50012-02.patch \ " SRC_URI[sha256sum] = "9eafe06f58a199b918e79d33d8aa03afb9ae0c11d18974dca0b44c2669cab6dd" From patchwork Fri Oct 9 16:42:02 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Marko X-Patchwork-Id: 100257 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7A44ACA601E for ; Fri, 9 Oct 2026 16:43:27 +0000 (UTC) Received: from mta-64-225.siemens.flowmailer.net (mta-64-225.siemens.flowmailer.net [185.136.64.225]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.129.1791564203189360977 for ; Fri, 09 Oct 2026 09:43:23 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=peter.marko@siemens.com header.s=fm1 header.b=nG3bF/Up; spf=pass (domain: rts-flowmailer.siemens.com, ip: 185.136.64.225, mailfrom: fm-256628-202610091643216e31360ed900020761-wcsp4d@rts-flowmailer.siemens.com) Received: by mta-64-225.siemens.flowmailer.net with ESMTPSA id 202610091643216e31360ed900020761 for ; Fri, 09 Oct 2026 18:43:21 +0200 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=fm1; d=siemens.com; i=peter.marko@siemens.com; h=Date:From:Subject:To:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding:Cc:References:In-Reply-To; bh=BeKA7cdzr73FxZJH+/WjzZr0M6gs35t1PH4bDL7zzDg=; b=nG3bF/UpsRML5r9gfuUAWndHdzma15mxZMhCWfaWXXVHXbdWBbos+Y+ffxrI5OQL3U6XXf VZeem7i6oZy3H2StJmdeWdqujzkxUKkotqR6RtiDSGwM+p+J8eLLZk1QYeRZrYbHsbFDa6Jt AHjBRbuwA+OiSa2N9VyM3TDtJh/8CTKrhHYCWujvhkdwhr0iTYrHe7CI5bHGfBbkXPmtQbZQ o+3Yn3xsbcw0xSFYPziDUJSeBrAoO+HqNDZMX+ePfqIpjsm79W3gDsafL8NBBqeYZDC/aMSW 5zUthyQHfDVUlLsJ132hl5NybiFkJw2V26BSB0bSfuy5werBG6QEUDMg==; From: Peter Marko To: openembedded-devel@lists.openembedded.org Cc: Peter Marko Subject: [meta-networking][scarthgap][PATCH 6/7] squid: patch CVE-2026-61642 Date: Fri, 9 Oct 2026 18:42:02 +0200 Message-ID: <20261009164203.1744134-6-peter.marko@siemens.com> In-Reply-To: <20261009164203.1744134-1-peter.marko@siemens.com> References: <20261009164203.1744134-1-peter.marko@siemens.com> MIME-Version: 1.0 X-Flowmailer-Platform: Siemens Feedback-ID: 519:519-256628:519-21489:flowmailer List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 09 Oct 2026 16:43:27 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130702 From: Peter Marko Pick SQUID-2026:6 patch per [1]. [1] https://github.com/squid-cache/squid/security/advisories/GHSA-537g-4gfh-w7m6 Signed-off-by: Peter Marko --- .../squid/files/CVE-2026-61642.patch | 43 +++++++++++++++++++ .../recipes-daemons/squid/squid_6.14.bb | 1 + 2 files changed, 44 insertions(+) create mode 100644 meta-networking/recipes-daemons/squid/files/CVE-2026-61642.patch diff --git a/meta-networking/recipes-daemons/squid/files/CVE-2026-61642.patch b/meta-networking/recipes-daemons/squid/files/CVE-2026-61642.patch new file mode 100644 index 0000000000..f5f2424504 --- /dev/null +++ b/meta-networking/recipes-daemons/squid/files/CVE-2026-61642.patch @@ -0,0 +1,43 @@ +From d06f48de8b8cc9a378cb91ecfe8e89b6e81696d2 Mon Sep 17 00:00:00 2001 +From: Amos Jeffries +Date: Sun, 31 May 2026 08:29:04 +0000 +Subject: [PATCH] HTTP/1.1: Transfer-Encoding:identity is prohibited (#2427) + +HTTP specification deprecated identity encoding but still allows +its use as an unknown encoding when the Transfer-Encoding +header is otherwise correctly used. + +Squid compliance update at the time kept accepting identity +encoding as it was being used by agents. The form supported was +Transfer-Encoding:identity. + +However, the HTTP specification explicitly requires that any +encoding MUST be wrapped within chunked encoding. + +As such the bare Transfer-Encoding:identity form Squid accepted +is explicitly prohibited. + +The correct Transfer-Encoding:identity,chunked syntax has been +rejected by Squid for nearly 5 years already without complaint. +So support is being dropped entirely here. + +CVE: CVE-2026-61642 +Upstream-Status: Backport [https://github.com/squid-cache/squid/commit/d06f48de8b8cc9a378cb91ecfe8e89b6e81696d2] +Signed-off-by: Peter Marko +--- + src/HttpHeader.cc | 2 -- + 1 file changed, 2 deletions(-) + +diff --git a/src/HttpHeader.cc b/src/HttpHeader.cc +index 3e06deab6..39422123f 100644 +--- a/src/HttpHeader.cc ++++ b/src/HttpHeader.cc +@@ -516,8 +516,6 @@ HttpHeader::parse(const char *header_start, size_t hdrLen, Http::ContentLengthIn + + if (rawTe.caseCmp("chunked") == 0) { + ; // leave header present for chunked() method +- } else if (rawTe.caseCmp("identity") == 0) { // deprecated. no coding +- delById(Http::HdrType::TRANSFER_ENCODING); + } else { + // This also rejects multiple encodings until we support them properly. + debugs(55, warnOnError, "WARNING: unsupported Transfer-Encoding used by client: " << rawTe); diff --git a/meta-networking/recipes-daemons/squid/squid_6.14.bb b/meta-networking/recipes-daemons/squid/squid_6.14.bb index ddaa4e48ac..0f07b38468 100644 --- a/meta-networking/recipes-daemons/squid/squid_6.14.bb +++ b/meta-networking/recipes-daemons/squid/squid_6.14.bb @@ -28,6 +28,7 @@ SRC_URI = "https://github.com/squid-cache/${BPN}/releases/download/SQUID_${PV_U} file://CVE-2026-47729.patch \ file://CVE-2026-50012-01.patch \ file://CVE-2026-50012-02.patch \ + file://CVE-2026-61642.patch \ " SRC_URI[sha256sum] = "9eafe06f58a199b918e79d33d8aa03afb9ae0c11d18974dca0b44c2669cab6dd" From patchwork Fri Oct 9 16:42:03 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Peter Marko X-Patchwork-Id: 100258 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7A6EDCA601D for ; Fri, 9 Oct 2026 16:43:37 +0000 (UTC) Received: from mta-64-225.siemens.flowmailer.net (mta-64-225.siemens.flowmailer.net [185.136.64.225]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.141.1791564212621854968 for ; Fri, 09 Oct 2026 09:43:32 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=peter.marko@siemens.com header.s=fm1 header.b=PittU4vj; spf=pass (domain: rts-flowmailer.siemens.com, ip: 185.136.64.225, mailfrom: fm-256628-20261009164330f5f126558e000207ee-zxdidi@rts-flowmailer.siemens.com) Received: by mta-64-225.siemens.flowmailer.net with ESMTPSA id 20261009164330f5f126558e000207ee for ; Fri, 09 Oct 2026 18:43:30 +0200 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=fm1; d=siemens.com; i=peter.marko@siemens.com; h=Date:From:Subject:To:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding:Cc:References:In-Reply-To; bh=zVjarkkLmyQxGgktjb7ONacSnZNqloOXCsOqbM1LywY=; b=PittU4vj+iNEHSnPJeE1IgTu9OOmPGrmMd72B1vphyAwTLcu+rS7qdcWng01yF7au/XWVZ UyJs/5yQJvUvgD73KqdVADIdto7qI+EXwtXnGuB4tXtf5b/Y7RaUHy59cFPMcCjFK3CXYM10 0jt41Ad6k5jDd4ofxHpoOnNAadaOM/w4P7nOFFec4spVmd6dSKmLtfj10WDNhq146Z5jlbsK frOMkmf1A861xqVf8qfw0obrdl8k5YRr9gx6Mnz5WCqDv65M5YkUvW/HFgGn8pgO1V/eMUv5 +FbGtO7A2yrhmj3sHyBxZgEM1e29SBCPgeTF45TwkRJvQaTPiFP7sCrA==; From: Peter Marko To: openembedded-devel@lists.openembedded.org Cc: Peter Marko Subject: [meta-networking][scarthgap][PATCH 7/7] squid: patch CVE-2026-104786 Date: Fri, 9 Oct 2026 18:42:03 +0200 Message-ID: <20261009164203.1744134-7-peter.marko@siemens.com> In-Reply-To: <20261009164203.1744134-1-peter.marko@siemens.com> References: <20261009164203.1744134-1-peter.marko@siemens.com> MIME-Version: 1.0 X-Flowmailer-Platform: Siemens Feedback-ID: 519:519-256628:519-21489:flowmailer List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 09 Oct 2026 16:43:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/130703 From: Peter Marko Pick SQUID-2026:7/SQUID-2026:8 patch per [1] and [2]. [1] https://github.com/squid-cache/squid/security/advisories/GHSA-j9pf-q9f6-v44c [2] https://github.com/squid-cache/squid/security/advisories/GHSA-vh99-xw7j-fx5c Signed-off-by: Peter Marko --- .../squid/files/CVE-2026-104786.patch | 131 ++++++++++++++++++ .../recipes-daemons/squid/squid_6.14.bb | 1 + 2 files changed, 132 insertions(+) create mode 100644 meta-networking/recipes-daemons/squid/files/CVE-2026-104786.patch diff --git a/meta-networking/recipes-daemons/squid/files/CVE-2026-104786.patch b/meta-networking/recipes-daemons/squid/files/CVE-2026-104786.patch new file mode 100644 index 0000000000..41e1fce735 --- /dev/null +++ b/meta-networking/recipes-daemons/squid/files/CVE-2026-104786.patch @@ -0,0 +1,131 @@ +From 8b3c2f2eea22886288edb47d4c30177bf8673650 Mon Sep 17 00:00:00 2001 +From: Francesco Chemolli <5175948+kinkie@users.noreply.github.com> +Date: Sun, 19 Jul 2026 21:22:29 +0000 +Subject: [PATCH] Protect base64 encoding buffers (#2447) + +Check bounds before base64-encoding data into fixed-size buffers. + +CVE: CVE-2026-104786 +Upstream-Status: Backport [https://github.com/squid-cache/squid/commit/8b3c2f2eea22886288edb47d4c30177bf8673650] +Signed-off-by: Peter Marko +--- + lib/sspwin32.cc | 1 + + src/adaptation/icap/ModXact.cc | 12 +++++++++--- + src/http.cc | 23 ++++++++++++++++++----- + src/peer_proxy_negotiate_auth.cc | 2 ++ + 4 files changed, 30 insertions(+), 8 deletions(-) + +diff --git a/lib/sspwin32.cc b/lib/sspwin32.cc +index 636731751..a07b5ceb3 100644 +--- a/lib/sspwin32.cc ++++ b/lib/sspwin32.cc +@@ -492,6 +492,7 @@ const char * WINAPI SSP_MakeChallenge(PVOID PNegotiateBuf, int NegotiateLen) + struct base64_encode_ctx ctx; + base64_encode_init(&ctx); + static char encoded[8192]; ++ assert(base64_encode_len(cbOut) < sizeof(encoded)); + size_t dstLen = base64_encode_update(&ctx, encoded, cbOut, reinterpret_cast(fResult)); + assert(dstLen < sizeof(encoded)); + dstLen += base64_encode_final(&ctx, encoded+dstLen); +diff --git a/src/adaptation/icap/ModXact.cc b/src/adaptation/icap/ModXact.cc +index 441bfc396..f3a187c19 100644 +--- a/src/adaptation/icap/ModXact.cc ++++ b/src/adaptation/icap/ModXact.cc +@@ -1402,12 +1402,18 @@ void Adaptation::Icap::ModXact::makeRequestHeaders(MemBuf &buf) + String vh=virgin.header->header.getById(Http::HdrType::PROXY_AUTHORIZATION); + buf.appendf("Proxy-Authorization: " SQUIDSTRINGPH "\r\n", SQUIDSTRINGPRINT(vh)); + } else if (request->extacl_user.size() > 0 && request->extacl_passwd.size() > 0) { ++ const auto userLen = request->extacl_user.size(); ++ const auto passwdLen = request->extacl_passwd.size(); ++ // +1 for the ':' separator between user and passwd ++ const auto plainLen = userLen + 1 + passwdLen; ++ if (plainLen > MAX_LOGIN_SZ) ++ throw TextException("extacl credentials too long for Proxy-Authorization", Here()); ++ char base64buf[base64_encode_len(MAX_LOGIN_SZ)]; + struct base64_encode_ctx ctx; + base64_encode_init(&ctx); +- char base64buf[base64_encode_len(MAX_LOGIN_SZ)]; +- size_t resultLen = base64_encode_update(&ctx, base64buf, request->extacl_user.size(), reinterpret_cast(request->extacl_user.rawBuf())); ++ auto resultLen = base64_encode_update(&ctx, base64buf, userLen, reinterpret_cast(request->extacl_user.rawBuf())); + resultLen += base64_encode_update(&ctx, base64buf+resultLen, 1, reinterpret_cast(":")); +- resultLen += base64_encode_update(&ctx, base64buf+resultLen, request->extacl_passwd.size(), reinterpret_cast(request->extacl_passwd.rawBuf())); ++ resultLen += base64_encode_update(&ctx, base64buf+resultLen, passwdLen, reinterpret_cast(request->extacl_passwd.rawBuf())); + resultLen += base64_encode_final(&ctx, base64buf+resultLen); + buf.appendf("Proxy-Authorization: Basic %.*s\r\n", (int)resultLen, base64buf); + } +diff --git a/src/http.cc b/src/http.cc +index df67fbbd2..3cf776ae8 100644 +--- a/src/http.cc ++++ b/src/http.cc +@@ -1853,8 +1853,12 @@ httpFixupAuthentication(HttpRequest * request, const HttpHeader * hdr_in, HttpHe + username = request->auth_user_request->username(); + #endif + +- blen = base64_encode_update(&ctx, loginbuf, strlen(username), reinterpret_cast(username)); +- blen += base64_encode_update(&ctx, loginbuf+blen, strlen(request->peer_login +1), reinterpret_cast(request->peer_login +1)); ++ const auto usernameLen = strlen(username); ++ const auto suffixLen = strlen(request->peer_login + 1); ++ if (usernameLen + suffixLen > MAX_LOGIN_SZ) ++ throw TextException("peer login credentials too long", Here()); ++ blen = base64_encode_update(&ctx, loginbuf, usernameLen, reinterpret_cast(username)); ++ blen += base64_encode_update(&ctx, loginbuf+blen, suffixLen, reinterpret_cast(request->peer_login +1)); + blen += base64_encode_final(&ctx, loginbuf+blen); + httpHeaderPutStrf(hdr_out, header, "Basic %.*s", (int)blen, loginbuf); + return; +@@ -1865,9 +1869,14 @@ httpFixupAuthentication(HttpRequest * request, const HttpHeader * hdr_in, HttpHe + (strcmp(request->peer_login, "PASS") == 0 || + strcmp(request->peer_login, "PROXYPASS") == 0)) { + +- blen = base64_encode_update(&ctx, loginbuf, request->extacl_user.size(), reinterpret_cast(request->extacl_user.rawBuf())); ++ const auto userLen = request->extacl_user.size(); ++ const auto passwdLen = request->extacl_passwd.size(); ++ // +1 for the ':' separator between user and passwd ++ if (userLen + 1 + passwdLen > MAX_LOGIN_SZ) ++ throw TextException("extacl credentials too long for peer login", Here()); ++ blen = base64_encode_update(&ctx, loginbuf, userLen, reinterpret_cast(request->extacl_user.rawBuf())); + blen += base64_encode_update(&ctx, loginbuf+blen, 1, reinterpret_cast(":")); +- blen += base64_encode_update(&ctx, loginbuf+blen, request->extacl_passwd.size(), reinterpret_cast(request->extacl_passwd.rawBuf())); ++ blen += base64_encode_update(&ctx, loginbuf+blen, passwdLen, reinterpret_cast(request->extacl_passwd.rawBuf())); + blen += base64_encode_final(&ctx, loginbuf+blen); + httpHeaderPutStrf(hdr_out, header, "Basic %.*s", (int)blen, loginbuf); + return; +@@ -1897,7 +1906,10 @@ httpFixupAuthentication(HttpRequest * request, const HttpHeader * hdr_in, HttpHe + } + #endif /* HAVE_KRB5 && HAVE_GSSAPI */ + +- blen = base64_encode_update(&ctx, loginbuf, strlen(request->peer_login), reinterpret_cast(request->peer_login)); ++ const auto loginLen = strlen(request->peer_login); ++ if (loginLen > MAX_LOGIN_SZ) ++ throw TextException("peer_login too long", Here()); ++ blen = base64_encode_update(&ctx, loginbuf, loginLen, reinterpret_cast(request->peer_login)); + blen += base64_encode_final(&ctx, loginbuf+blen); + httpHeaderPutStrf(hdr_out, header, "Basic %.*s", (int)blen, loginbuf); + return; +@@ -2024,6 +2036,7 @@ HttpStateData::httpBuildRequestHeader(HttpRequest * request, + /* append Authorization if known in URL, not in header and going direct */ + if (!hdr_out->has(Http::HdrType::AUTHORIZATION)) { + if (flags.toOrigin && !request->url.userInfo().isEmpty()) { ++ Assure(request->url.userInfo().length() < MAX_URL*2); + static char result[base64_encode_len(MAX_URL*2)]; // should be big enough for a single URI segment + struct base64_encode_ctx ctx; + base64_encode_init(&ctx); +diff --git a/src/peer_proxy_negotiate_auth.cc b/src/peer_proxy_negotiate_auth.cc +index d0f36477e..2fcad6ebb 100644 +--- a/src/peer_proxy_negotiate_auth.cc ++++ b/src/peer_proxy_negotiate_auth.cc +@@ -17,6 +17,7 @@ + #define GSSKRB_APPLE_DEPRECATED(x) + #endif + ++#include "base/Assure.h" + #include "base64.h" + #include "compat/krb5.h" + #include "debug/Stream.h" +@@ -549,6 +550,7 @@ char *peer_proxy_negotiate_auth(char *principal_name, char *proxy, int flags) { + static char b64buf[8192]; // XXX: 8KB only because base64_encode_bin() used to. + struct base64_encode_ctx ctx; + base64_encode_init(&ctx); ++ Assure(base64_encode_len(output_token.length) < sizeof(b64buf)); + size_t blen = base64_encode_update(&ctx, b64buf, output_token.length, reinterpret_cast(output_token.value)); + blen += base64_encode_final(&ctx, b64buf+blen); + b64buf[blen] = '\0'; diff --git a/meta-networking/recipes-daemons/squid/squid_6.14.bb b/meta-networking/recipes-daemons/squid/squid_6.14.bb index 0f07b38468..0b0eddb4aa 100644 --- a/meta-networking/recipes-daemons/squid/squid_6.14.bb +++ b/meta-networking/recipes-daemons/squid/squid_6.14.bb @@ -29,6 +29,7 @@ SRC_URI = "https://github.com/squid-cache/${BPN}/releases/download/SQUID_${PV_U} file://CVE-2026-50012-01.patch \ file://CVE-2026-50012-02.patch \ file://CVE-2026-61642.patch \ + file://CVE-2026-104786.patch \ " SRC_URI[sha256sum] = "9eafe06f58a199b918e79d33d8aa03afb9ae0c11d18974dca0b44c2669cab6dd"