PT-2026-28159 · Squid+4 · Squid+5

CVE-2026-32748

·

Published

2026-01-01

·

Updated

2026-07-06

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L
Name of the Vulnerable Software and Affected Versions Squid versions prior to 7.5
Description A flaw exists in the handling of Internet Cache Protocol (ICP) traffic. Due to premature resource release and heap Use-After-Free bugs (where the program continues to use a memory address after it has been freed), a remote attacker can send specially crafted ICP traffic to cause a denial of service or potentially obtain small amounts of sensitive information. This issue specifically affects deployments where ICP support is explicitly enabled by configuring a non-zero icp port. This cannot be mitigated by using icp access rules.
Recommendations Update to version 7.5. As a temporary mitigation, disable ICP support by setting the icp port to zero.

Exploit

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:6301
ALSA-2026:8119
ALSA-2026:8317
BDU:2026-07191
CVE-2026-32748
GHSA-F9P7-3JQG-HHVQ
MGASA-2026-0094
RHSA-2026:10255
RHSA-2026:10256
RHSA-2026:10257
RHSA-2026:11901
RHSA-2026:20564
RHSA-2026:20565
RHSA-2026:20580
RHSA-2026:6301
RHSA-2026:8119
RHSA-2026:8317
RHSA-2026:8880
RHSA-2026:9220
USN-8157-1

Affected Products

Linuxmint
Red Os
Rocky Linux
Squid
Squid Cache
Ubuntu