Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-32748

Опубликовано: 26 мар. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero icp_port). This problem cannot be mitigated by denying ICP queries using icp_access rules. This bug is fixed in Squid version 7.5.

A flaw was found in Squid. A remote attacker can exploit this vulnerability by sending specially crafted ICP (Internet Cache Protocol) traffic. This can lead to a Denial of Service (DoS) due to premature resource release and use-after-free vulnerabilities. This attack is possible in Squid deployments with explicitly enabled ICP support.

Отчет

This Important flaw in Squid can lead to a Denial of Service when processing specially crafted Internet Cache Protocol (ICP) traffic. This vulnerability affects Red Hat products running Squid if ICP support is explicitly enabled by configuring a non-zero icp_port. Deployments where ICP is not enabled by default are not affected.

Меры по смягчению последствий

To mitigate this issue, ensure that ICP support is not explicitly enabled in the Squid configuration. This can be achieved by commenting out or setting icp_port to 0 in the squid.conf file. After modifying the configuration, the Squid service must be reloaded or restarted for the changes to take effect. Example:

# icp_port 3130

or

icp_port 0

Warning: Reloading or restarting the Squid service may temporarily interrupt proxy services.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6squidOut of support scope
Red Hat Enterprise Linux 6squid34Out of support scope
Red Hat Enterprise Linux 10squidFixedRHSA-2026:811914.04.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportsquidFixedRHSA-2026:1190129.04.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupportsquidFixedRHSA-2026:888020.04.2026
Red Hat Enterprise Linux 8squidFixedRHSA-2026:831715.04.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportsquidFixedRHSA-2026:2056426.05.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnsquidFixedRHSA-2026:2056426.05.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportsquidFixedRHSA-2026:2056526.05.2026
Red Hat Enterprise Linux 8.6 Telecommunications Update ServicesquidFixedRHSA-2026:2056526.05.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-826
https://bugzilla.redhat.com/show_bug.cgi?id=2451577Squid: Squid: Denial of Service via crafted ICP traffic

EPSS

Процентиль: 95%
0.08931
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero `icp_port`). This problem _cannot_ be mitigated by denying ICP queries using `icp_access` rules. This bug is fixed in Squid version 7.5.

CVSS3: 7.5
nvd
4 месяца назад

Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero `icp_port`). This problem _cannot_ be mitigated by denying ICP queries using `icp_access` rules. This bug is fixed in Squid version 7.5.

CVSS3: 7.5
msrc
4 месяца назад

Squid has Denial of Service in ICP Response handling

CVSS3: 7.5
debian
4 месяца назад

Squid is a caching proxy for the Web. Prior to version 7.5, due to pre ...

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость прокси-сервера Squid, связанная с неправильной блокировкой ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 95%
0.08931
Низкий

7.5 High

CVSS3