OESA-2026-2726

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-2726
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-2726.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-2726
Upstream
  • CVE-2026-47729
  • CVE-2026-50012
Published
2026-06-24T13:12:55Z
Modified
2026-06-24T13:30:10.402068009Z
Summary
squid security update
Details

Squid is a high-performance proxy caching server. It handles all requests in a single, non-blocking, I/O-driven process and keeps meta data and implements negative caching of failed requests.

Security Fix(es):

'Hi all,', "CVE-2026-47729\n\nDue to a Improper Validation of Syntactic Correctness of Input\nbug, Squid is vulnerable to a Out-of-bounds Read\nattack against the FTP gateway.\n\nThis problem allows a trusted client to perform an Out-of-Bounds\nRead from random unrelated transactions when accessing a\nmisbehaving FTP server through Squid's gateway feature.\n\n<", '>\n\n\n\nCVE-2026-50012\n\nDue to an Improper Input Validation bug, Squid is vulnerable to\na Heap-based Buffer Overflow attack against cache digests.\n\nThis problem allows a trusted server to perform a Heap-based\nBuffer Overflow when sending maliciously crafted replies to\ncache_digest request messages.\n\nThis attack is limited to Squid instances that have been\ncompiled with the --enable-cache-digests option.\n\n<', '>', 'Amos Jeffries\nThe Squid Software Foundation'

'Hi all,', "CVE-2026-47729\n\nDue to a Improper Validation of Syntactic Correctness of Input\nbug, Squid is vulnerable to a Out-of-bounds Read\nattack against the FTP gateway.\n\nThis problem allows a trusted client to perform an Out-of-Bounds\nRead from random unrelated transactions when accessing a\nmisbehaving FTP server through Squid's gateway feature.\n\n<", '>\n\n\n\nCVE-2026-50012\n\nDue to an Improper Input Validation bug, Squid is vulnerable to\na Heap-based Buffer Overflow attack against cache digests.\n\nThis problem allows a trusted server to perform a Heap-based\nBuffer Overflow when sending maliciously crafted replies to\ncache_digest request messages.\n\nThis attack is limited to Squid instances that have been\ncompiled with the --enable-cache-digests option.\n\n<', '>', 'Amos Jeffries\nThe Squid Software Foundation'

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:22.03-LTS-SP4 / squid

Package

Name
squid
Purl
pkg:rpm/openEuler/squid&distro=openEuler-22.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9-31.oe2203sp4

Ecosystem specific

{
    "src": [
        "squid-4.9-31.oe2203sp4.src.rpm"
    ],
    "aarch64": [
        "squid-4.9-31.oe2203sp4.aarch64.rpm",
        "squid-debuginfo-4.9-31.oe2203sp4.aarch64.rpm",
        "squid-debugsource-4.9-31.oe2203sp4.aarch64.rpm"
    ],
    "x86_64": [
        "squid-4.9-31.oe2203sp4.x86_64.rpm",
        "squid-debuginfo-4.9-31.oe2203sp4.x86_64.rpm",
        "squid-debugsource-4.9-31.oe2203sp4.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2726.json"

openEuler:24.03-LTS-SP1 / squid

Package

Name
squid
Purl
pkg:rpm/openEuler/squid&distro=openEuler-24.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.6-9.oe2403sp1

Ecosystem specific

{
    "src": [
        "squid-6.6-9.oe2403sp1.src.rpm"
    ],
    "x86_64": [
        "squid-6.6-9.oe2403sp1.x86_64.rpm",
        "squid-debuginfo-6.6-9.oe2403sp1.x86_64.rpm",
        "squid-debugsource-6.6-9.oe2403sp1.x86_64.rpm"
    ],
    "aarch64": [
        "squid-6.6-9.oe2403sp1.aarch64.rpm",
        "squid-debuginfo-6.6-9.oe2403sp1.aarch64.rpm",
        "squid-debugsource-6.6-9.oe2403sp1.aarch64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2726.json"

openEuler:24.03-LTS-SP3 / squid

Package

Name
squid
Purl
pkg:rpm/openEuler/squid&distro=openEuler-24.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.6-9.oe2403sp3

Ecosystem specific

{
    "src": [
        "squid-6.6-9.oe2403sp3.src.rpm"
    ],
    "aarch64": [
        "squid-6.6-9.oe2403sp3.aarch64.rpm",
        "squid-debuginfo-6.6-9.oe2403sp3.aarch64.rpm",
        "squid-debugsource-6.6-9.oe2403sp3.aarch64.rpm"
    ],
    "x86_64": [
        "squid-6.6-9.oe2403sp3.x86_64.rpm",
        "squid-debuginfo-6.6-9.oe2403sp3.x86_64.rpm",
        "squid-debugsource-6.6-9.oe2403sp3.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2726.json"

openEuler:20.03-LTS-SP4 / squid

Package

Name
squid
Purl
pkg:rpm/openEuler/squid&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9-27.oe2003sp4

Ecosystem specific

{
    "src": [
        "squid-4.9-27.oe2003sp4.src.rpm"
    ],
    "aarch64": [
        "squid-4.9-27.oe2003sp4.aarch64.rpm",
        "squid-debuginfo-4.9-27.oe2003sp4.aarch64.rpm",
        "squid-debugsource-4.9-27.oe2003sp4.aarch64.rpm"
    ],
    "x86_64": [
        "squid-4.9-27.oe2003sp4.x86_64.rpm",
        "squid-debuginfo-4.9-27.oe2003sp4.x86_64.rpm",
        "squid-debugsource-4.9-27.oe2003sp4.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2726.json"