Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33526

Опубликовано: 26 мар. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero icp_port). This problem cannot be mitigated by denying ICP queries using icp_access rules. Version 7.5 contains a patch.

A flaw was found in Squid. A remote attacker can exploit a heap Use-After-Free vulnerability when handling ICP (Internet Cache Protocol) traffic. This allows them to perform a reliable and repeatable Denial of Service (DoS) attack, making the Squid service unavailable. This attack is limited to deployments where ICP support is explicitly enabled.

Отчет

Important: A heap Use-After-Free vulnerability in Squid's ICP handling can lead to a denial of service. This flaw affects Red Hat products where the Squid proxy is configured to explicitly enable Internet Cache Protocol (ICP) support by setting a non-zero icp_port. Deployments with default configurations, where ICP is typically disabled, are not affected.

Меры по смягчению последствий

To mitigate this issue, disable ICP support in Squid by ensuring that icp_port is set to 0 in the squid.conf configuration file. This will prevent Squid from processing ICP traffic and eliminate the attack vector. After modifying the configuration, the Squid service must be restarted for the changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6squidOut of support scope
Red Hat Enterprise Linux 6squid34Out of support scope
Red Hat Enterprise Linux 10squidFixedRHSA-2026:811914.04.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportsquidFixedRHSA-2026:1190129.04.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupportsquidFixedRHSA-2026:888020.04.2026
Red Hat Enterprise Linux 8squidFixedRHSA-2026:831715.04.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportsquidFixedRHSA-2026:2056426.05.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnsquidFixedRHSA-2026:2056426.05.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportsquidFixedRHSA-2026:2056526.05.2026
Red Hat Enterprise Linux 8.6 Telecommunications Update ServicesquidFixedRHSA-2026:2056526.05.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2451574squid: Squid: Denial of Service via heap Use-After-Free vulnerability in ICP handling

EPSS

Процентиль: 95%
0.08942
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero `icp_port`). This problem _cannot_ be mitigated by denying ICP queries using `icp_access` rules. Version 7.5 contains a patch.

CVSS3: 7.5
nvd
4 месяца назад

Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero `icp_port`). This problem _cannot_ be mitigated by denying ICP queries using `icp_access` rules. Version 7.5 contains a patch.

CVSS3: 7.5
msrc
4 месяца назад

Squid vulnerable to Denial of Service in ICP Request handling

CVSS3: 7.5
debian
4 месяца назад

Squid is a caching proxy for the Web. Prior to version 7.5, due to hea ...

CVSS3: 8.6
fstec
4 месяца назад

Уязвимость прокси-сервера Squid, связанная с использованием памяти после её освобождения, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 95%
0.08942
Низкий

7.5 High

CVSS3