Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-32748

Опубликовано: 26 мар. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero icp_port). This problem cannot be mitigated by denying ICP queries using icp_access rules. This bug is fixed in Squid version 7.5.

A flaw was found in Squid. A remote attacker can exploit this vulnerability by sending specially crafted ICP (Internet Cache Protocol) traffic. This can lead to a Denial of Service (DoS) due to premature resource release and use-after-free vulnerabilities. This attack is possible in Squid deployments with explicitly enabled ICP support.

Отчет

This Important flaw in Squid can lead to a Denial of Service when processing specially crafted Internet Cache Protocol (ICP) traffic. This vulnerability affects Red Hat products running Squid if ICP support is explicitly enabled by configuring a non-zero icp_port. Deployments where ICP is not enabled by default are not affected.

Меры по смягчению последствий

To mitigate this issue, ensure that ICP support is not explicitly enabled in the Squid configuration. This can be achieved by commenting out or setting icp_port to 0 in the squid.conf file. After modifying the configuration, the Squid service must be reloaded or restarted for the changes to take effect. Example:

# icp_port 3130

or

icp_port 0

Warning: Reloading or restarting the Squid service may temporarily interrupt proxy services.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10squidAffected
Red Hat Enterprise Linux 6squidOut of support scope
Red Hat Enterprise Linux 6squid34Out of support scope
Red Hat Enterprise Linux 7squidAffected
Red Hat Enterprise Linux 8squid:4/squidAffected
Red Hat Enterprise Linux 9squidFixedRHSA-2026:630131.03.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-826
https://bugzilla.redhat.com/show_bug.cgi?id=2451577Squid: Squid: Denial of Service via crafted ICP traffic

EPSS

Процентиль: 80%
0.01281
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
13 дней назад

Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero `icp_port`). This problem _cannot_ be mitigated by denying ICP queries using `icp_access` rules. This bug is fixed in Squid version 7.5.

CVSS3: 7.5
nvd
13 дней назад

Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero `icp_port`). This problem _cannot_ be mitigated by denying ICP queries using `icp_access` rules. This bug is fixed in Squid version 7.5.

CVSS3: 7.5
msrc
12 дней назад

Squid has Denial of Service in ICP Response handling

CVSS3: 7.5
debian
13 дней назад

Squid is a caching proxy for the Web. Prior to version 7.5, due to pre ...

oracle-oval
8 дней назад

ELSA-2026-6301: squid security update (IMPORTANT)

EPSS

Процентиль: 80%
0.01281
Низкий

7.5 High

CVSS3