haproxy: fix CVE-2026-90678

Apply the version-specific upstream HTTP/3 parser fix.

Assisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)
Not-cherry-picked-because: HAProxy 3.3 requires its version-specific upstream backport
This commit is contained in:
Gerhard Schwanzer
2026-09-16 09:17:29 +02:00
parent 598c4fca68
commit 03b503e252

View File

@@ -5,6 +5,7 @@
sslLibrary ? "openssl",
stdenv,
lib,
fetchpatch,
fetchurl,
nixosTests,
zlib,
@@ -40,6 +41,15 @@ stdenv.mkDerivation (finalAttrs: {
hash = "sha256-ywGFCNBymseyaGlEqKk37a3bB0ThDNEFfdZQFQzcKD4=";
};
patches = [
# Remove once the packaged release fixes CVE-2026-90678.
(fetchpatch {
name = "CVE-2026-90678.patch";
url = "https://github.com/haproxy/haproxy/commit/81482d95aa6dfbd3f6eadd2f3650f256dc0b4e03.patch";
hash = "sha256-jmupw5lPzWqutD4RpAECetFNLzXvejWS4PCoMW+ZPtM=";
})
];
buildInputs = [
sslPkg
zlib