PT-2026-28159 · Squid+4 · Squid+5
CVE-2026-32748
·
Published
2026-01-01
·
Updated
2026-07-06
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L |
Name of the Vulnerable Software and Affected Versions
Squid versions prior to 7.5
Description
A flaw exists in the handling of Internet Cache Protocol (ICP) traffic. Due to premature resource release and heap Use-After-Free bugs (where the program continues to use a memory address after it has been freed), a remote attacker can send specially crafted ICP traffic to cause a denial of service or potentially obtain small amounts of sensitive information. This issue specifically affects deployments where ICP support is explicitly enabled by configuring a non-zero
icp port. This cannot be mitigated by using icp access rules.Recommendations
Update to version 7.5.
As a temporary mitigation, disable ICP support by setting the
icp port to zero.Exploit
Fix
DoS
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Red Os
Rocky Linux
Squid
Squid Cache
Ubuntu