From 6d9ada19a742212d3d8e011d54fa616d9111acc7 Mon Sep 17 00:00:00 2001 From: CentOS Sources Date: Mar 29 2022 16:42:57 +0000 Subject: import varnish-6.0.8-1.module+el8.5.0+14089+03a0c2cc.1 --- diff --git a/SOURCES/varnish-6.0.8.CVE-2022-23959.patch b/SOURCES/varnish-6.0.8.CVE-2022-23959.patch new file mode 100644 index 0000000..27e3861 --- /dev/null +++ b/SOURCES/varnish-6.0.8.CVE-2022-23959.patch @@ -0,0 +1,13 @@ +diff --git a/bin/varnishd/cache/cache_req_body.c b/bin/varnishd/cache/cache_req_body.c +index 463b75b..982bd73 100644 +--- a/bin/varnishd/cache/cache_req_body.c ++++ b/bin/varnishd/cache/cache_req_body.c +@@ -254,6 +254,8 @@ VRB_Ignore(struct req *req) + if (req->req_body_status == REQ_BODY_WITH_LEN || + req->req_body_status == REQ_BODY_WITHOUT_LEN) + (void)VRB_Iterate(req, httpq_req_body_discard, NULL); ++ if (req->req_body_status == REQ_BODY_FAIL) ++ req->doclose = SC_RX_BODY; + return(0); + } + diff --git a/SPECS/varnish.spec b/SPECS/varnish.spec index bcd941a..03b615a 100644 --- a/SPECS/varnish.spec +++ b/SPECS/varnish.spec @@ -19,7 +19,7 @@ Summary: High-performance HTTP accelerator Name: varnish Version: 6.0.8 -Release: 1%{?dist} +Release: 1%{?dist}.1 License: BSD Group: System Environment/Daemons URL: https://www.varnish-cache.org/ @@ -32,6 +32,9 @@ Patch9: varnish-5.1.1.fix_python_version.patch # https://github.com/varnishcache/varnish-cache/commit/5220c394232c25bb7a807a35e7394059ecefa821#diff-2279587378a4426edde05f42e1acca5e Patch11: varnish-6.0.0.fix_el6_fortify_source.patch +# https://bugzilla.redhat.com/show_bug.cgi?id=2045031 +Patch100: varnish-6.0.8.CVE-2022-23959.patch + Obsoletes: varnish-libs %if %{with python3} @@ -140,6 +143,8 @@ sed -i '8 i\RPM_BUILD_ROOT=%{buildroot}' find-provides %patch11 -p0 %endif +%patch100 -p1 + %build %if 0%{?rhel} == 6 export CFLAGS="%{optflags} -fPIC" @@ -371,6 +376,10 @@ fi %changelog +* Tue Feb 01 2022 Luboš Uhliarik - 6.0.8-1.1 +- Resolves: #2047648 - CVE-2022-23959 varnish:6/varnish: Varnish HTTP/1 Request + Smuggling Vulnerability + * Thu Jul 22 2021 Luboš Uhliarik - 6.0.8-1 - new version 6.0.8 - Resolves: #1982862 - CVE-2021-36740 varnish:6/varnish: HTTP/2 request