Re: [Buildroot] [PATCH] packages/haproxy: security bump to version 2.6.32
Peter Korsgaard <[email protected]>
| Newsgroups | net.busybox.buildroot |
|---|---|
| Message-ID | <[email protected]> |
>>>>> "Fred" == Fred Lefranc <[email protected]> writes: > Bugfix release with large number of (security) fixes. > HAProxy 2.6.32 was released on 2026/07/29. It added 33 new commits > after version 2.6.31. > As for the 2.8.27, the announce is an expurgated copy-paste of the 3.4.3 > announce: > * stats: Two issues about the stats page, reported by Red Hat/AISLE > Research, were fixed. > Proxies updated through the stats page while in "stats admin" mode were > not subject to the "stats scope" filtering, meaning a scope meant to > restrict which proxies are visible/actionable could be silently bypassed > on POST requests. > Separately, POST requests to the stats interface did not validate that the > Origin (or Referer) header matched the Host, which is now checked to > mitigate CSRF attacks. > * ssl-gencert: A memory leak on every certificate generation was fixed. > Two temporary buffers were not freed after generating a certificate on the > fly, leaking memory each time a new SNI triggered certificate > generation. This issue was reported by Red Hat/AISLE Research. > * sample/protobuf: buffer overflows after pointer-shift converters, reported > by Red Hat/AISLE Research and Charles Vosburgh, were fixed. > Several converters (protobuf/ungrpc field extraction, ltrim()) > move the sample's data pointer forward on success but did not shrink the > sample's recorded buffer capacity accordingly. A converter chained > afterwards that relies on that capacity (e.g. padding via memset()) could > then write past the end of the buffer, leading to heap corruption or a > worker crash. All the affected converters now adjust the capacity > together with the pointer. > * protobuf: A nested-path validation bypass reported by Red Hat/AISLE > Research was fixed. > The protobuf field lookup used for the protobuf()/ungrpc() converters did > not strictly enforce hierarchical boundaries, so a flat sibling field > could incorrectly satisfy a nested-path lookup (e.g. matching a root-level > field as if it were nested under a parent). The lookup was rewritten as a > strict, non-recursive path walker that correctly bounds each nesting > level. > Separately, a crash because of deprecated protobuf group wire types was > fixed. These wire types are now explicitly rejected. > * http-fetch: Two crashes reachable from health-check configurations were > fixed. > "res.body"/"res.hdr"/... and similar response fetches assumed the > health-check receive buffer always held an HTX message, which is only true > for actual HTTP checks; on a plain TCP check, a hostile/misbehaving server > could craft the first bytes of its reply to be misinterpreted as HTX > internal fields, causing a wild read and worker crash (or leaking > arbitrary process memory). > Separately, "capture.req.hdr"/"capture.res.hdr" only validated the upper > bound of their index argument, so a negative capture id was accepted at > boot and dereferenced an out-of-bounds array entry at runtime, crashing > the worker on the very first request. > * slz: Several issues were fixed in the SLZ library. > A stream alternating many literals in the 144-255 range with cheap > back-references could keep inflating indefinitely instead of falling > back to a stored block, exceeding the library's documented worst-case > output size by several percent. A new accounting mechanism now bounds > this overhead. Practical impact on haproxy requires tune.bufsize above > ~43 kB with the default reserve. > Five small correctness fixes inherited from upstream libslz were also > backported: Avoid reading up to a few bytes past the end of very short > inputs on architectures without fast unaligned access; stop appending an > extra, misplaced block to an already-finished deflate/gzip/zlib stream > (which could corrupt the trailing checksum in ~2% of fuzzed streams); fix > the Adler32 checksum accumulator sign handling on 32-bit systems > (affecting the zlib format only); avoid an undefined-behaviour signed left > shift when assembling input words byte by byte; and use the exact bit cost > when deciding whether to emit the last literals of a block as a stored > block, avoiding compressed output slightly larger than the documented > worst case. > * peers: A heap overflow when replicating large stick-table dictionary > entries was fixed. > peer_prepare_updatemsg() never verified that a stick-table entry's > dictionary value (e.g. server_key, up to ~16 kB) actually fit in the > update message being built. Since the peers protocol is plain-text and > unauthenticated, a rogue or compromised peer could plant an oversized > entry that overflows the 16 kB trash buffer as soon as the victim > replicates ("teaches") it, confirmed as a heap-buffer-overflow write. The > function now checks the available room before encoding and fails cleanly > if it doesn't fit. This was reported and fixes by Matt Suiche from Tolmo > Inc. > And, as usual, the bunch of minor fixes here and there, mainly raised during > AI-assisted code reviews. Most were never noticed: > * HTX API: Some bugs about how the HTX API was used were fixed here and > there. > * http-act: Double-frees and a couple of state bugs on parsing errors were > fixed. > * http-fetch/http-ana/http-htx: Few out-of-bounds reads were fixed. > * http-conv: The last input character could be lost when calling url-dec > converter, when the input buffer was full. This was fixed by failing the > converter in that case. > * mux-h1: An extra 200ms delay was observed on some H2-to-H1 messages > because the end of the message was not always properly detected. This > case is now properly handled. > * sample: An edge case in be2hex() was fixed. > For more details, see the announcement: > https://www.mail-archive.com/[email protected]/msg47353.html > Signed-off-by: Fred Lefranc <[email protected]> Committed, thanks. -- Bye, Peter Korsgaard _______________________________________________ buildroot mailing list [email protected] https://lists.buildroot.org/mailman/listinfo/buildroot