PT-2026-28165 · Squid+4 · Squid+5
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H |
Name of the Vulnerable Software and Affected Versions
Squid versions prior to 7.5
Description
A heap Use-After-Free issue exists when handling Internet Cache Protocol (ICP) traffic. This allows a remote attacker to perform a reliable and repeatable Denial of Service attack, making the service unavailable. The issue is limited to deployments where ICP support is explicitly enabled by configuring a non-zero
icp port. This cannot be mitigated by using icp access rules. Use-After-Free is a condition where a program continues to use a pointer after it has been freed, which can lead to crashes or memory corruption.Recommendations
Update to version 7.5.
As a temporary workaround, disable ICP support by setting the
icp port to zero.Exploit
Fix
DoS
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Red Os
Rocky Linux
Squid
Squid Cache
Ubuntu