From 3909ba48e9f863f0e9c4e004de858546bfdf1e24 Mon Sep 17 00:00:00 2001 From: Gerhard Schwanzer Date: Wed, 16 Sep 2026 09:17:29 +0200 Subject: [PATCH] haproxy: fix CVE-2026-90678 Apply the upstream HTTP/3 parser fix. Assisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol) --- pkgs/by-name/ha/haproxy/package.nix | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/pkgs/by-name/ha/haproxy/package.nix b/pkgs/by-name/ha/haproxy/package.nix index 91ae06d87ad2..a64d548a4c8c 100644 --- a/pkgs/by-name/ha/haproxy/package.nix +++ b/pkgs/by-name/ha/haproxy/package.nix @@ -5,6 +5,7 @@ sslLibrary ? "openssl", stdenv, lib, + fetchpatch2, fetchurl, nixosTests, zlib, @@ -40,6 +41,15 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-sMUFPE1GhA7N7jklc2/po95kclWbQ8aRg9cOWT2RM98="; }; + patches = [ + # Remove once the packaged release fixes CVE-2026-90678. + (fetchpatch2 { + name = "CVE-2026-90678.patch"; + url = "https://github.com/haproxy/haproxy/commit/86a4ebc761a278838e8cb06f3a292282ba704c65.patch?full_index=1"; + hash = "sha256-GTI9c1Y3d7DN2m11eODM3FkY2Aitrndi3CTI2Tr95OU="; + }) + ]; + buildInputs = [ sslPkg zlib