diff --git a/pkgs/servers/http/trafficserver/9.1.4-CVE-2023-33934.supplemental.patch b/pkgs/servers/http/trafficserver/9.1.4-CVE-2023-33934.supplemental.patch new file mode 100644 index 000000000000..7f90113ceaef --- /dev/null +++ b/pkgs/servers/http/trafficserver/9.1.4-CVE-2023-33934.supplemental.patch @@ -0,0 +1,101 @@ +Based on upstream fbb6acb1caac752e6719b912e0de971691c1ad99, adjusted to +apply cleanly to 9.1.4 + +diff --git a/proxy/hdrs/URL.cc b/proxy/hdrs/URL.cc +index 8124bb9f2..90973bbdd 100644 +--- a/proxy/hdrs/URL.cc ++++ b/proxy/hdrs/URL.cc +@@ -1524,8 +1524,13 @@ done: + // correcting this behavior, therefore, we maintain the current + // functionality but add state to determine whether the path was + // absolutely empty so we can reconstruct such URLs. +- ++path_start; ++ // ++ // Remove all preceding slashes ++ while (path_start < path_end && *path_start == '/') { ++ ++path_start; ++ } + } ++ + url_path_set(heap, url, path_start, path_end - path_start, copy_strings); + } else if (!nothing_after_host) { + // There was no path set via '/': it is absolutely empty. However, if there +@@ -1577,7 +1582,10 @@ url_parse_http_regex(HdrHeap *heap, URLImpl *url, const char **start, const char + cur = static_cast(memchr(cur, '/', end - cur)); + if (cur) { + host_end = cur; +- ++cur; ++ // Remove all preceding slashes ++ while (cur < end && *cur == '/') { ++ cur++; ++ } + } else { + host_end = cur = end; + } +diff --git a/proxy/hdrs/unit_tests/test_URL.cc b/proxy/hdrs/unit_tests/test_URL.cc +index 115aeee5d..a06d1d5d0 100644 +--- a/proxy/hdrs/unit_tests/test_URL.cc ++++ b/proxy/hdrs/unit_tests/test_URL.cc +@@ -173,6 +173,14 @@ constexpr bool VERIFY_HOST_CHARACTERS = true; + + // clang-format off + std::vector url_parse_test_cases = { ++ { ++ "///dir////index.html", ++ "/dir////index.html", ++ VERIFY_HOST_CHARACTERS, ++ "/dir////index.html", ++ IS_VALID, ++ IS_VALID ++ }, + { + "/index.html", + "/index.html", +@@ -183,9 +191,9 @@ std::vector url_parse_test_cases = { + }, + { + "//index.html", +- "//index.html", ++ "/index.html", + VERIFY_HOST_CHARACTERS, +- "//index.html", ++ "/index.html", + IS_VALID, + IS_VALID + }, +@@ -215,9 +223,9 @@ std::vector url_parse_test_cases = { + // with two slash characters ("//"). We have historically allowed this, + // however, and will continue to do so. + "https:////", +- "https:////", ++ "https:///", + VERIFY_HOST_CHARACTERS, +- "https:////", ++ "https:///", + IS_VALID, + IS_VALID + }, +@@ -257,9 +265,9 @@ std::vector url_parse_test_cases = { + }, + { + "https://www.example.com//", +- "https://www.example.com//", ++ "https://www.example.com/", + VERIFY_HOST_CHARACTERS, +- "https://www.example.com//", ++ "https://www.example.com/", + IS_VALID, + IS_VALID + }, +@@ -313,9 +321,9 @@ std::vector url_parse_test_cases = { + }, + { + "https://www.example.com//a/path", +- "https://www.example.com//a/path", ++ "https://www.example.com/a/path", + VERIFY_HOST_CHARACTERS, +- "https://www.example.com//a/path", ++ "https://www.example.com/a/path", + IS_VALID, + IS_VALID + }, diff --git a/pkgs/servers/http/trafficserver/default.nix b/pkgs/servers/http/trafficserver/default.nix index b47d71a1ab74..ce6200af02b4 100644 --- a/pkgs/servers/http/trafficserver/default.nix +++ b/pkgs/servers/http/trafficserver/default.nix @@ -74,6 +74,18 @@ stdenv.mkDerivation rec { }) ./9.1.4-CVE-2023-33933.patch ./9.1.4-CVE-2023-30631.patch + + (fetchpatch { + name = "CVE-2022-47185.patch"; + url = "https://github.com/apache/trafficserver/commit/5d0835ea5a57003798497d07331fa4f89823c750.patch"; + sha256 = "sha256-h4vaa7UwWFmJ9ZOtZsHuExcZQMFG8IER4WFp1r7Ym+U="; + }) + (fetchpatch { + name = "CVE-2023-33934.patch"; + url = "https://github.com/apache/trafficserver/commit/32d93ad084d18ee592754e3736d960a4fd8ddfd2.patch"; + sha256 = "sha256-z3rCUe7MhKwnn8wzW6ba5ojdSAIhHkL/PNZqm04gNf4="; + }) + ./9.1.4-CVE-2023-33934.supplemental.patch ]; # NOTE: The upstream README indicates that flex is needed for some features,