Use After Free in Squid - CVE-2026-33526

 

Use After Free in Squid - CVE-2026-33526

Published: March 25, 2026


Vulnerability identifier: #VU124610
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33526
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to heap use-after-free in ICP request handling when processing ICP traffic. A remote attacker can send a specially crafted ICP request to cause a denial of service.

The attack is limited to Squid deployments that have ICP support enabled via a non-zero icp_port configuration.


Affected software

Squid
Debian Linux
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
openEuler
Ubuntu
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libecap-devel
libecap
squid
squid-debuginfo
squid-debugsource
squid (Red Hat package)
squid (Ubuntu package)
squid (Debian package)

How to mitigate CVE-2026-33526

Install security update from vendor's website.

Squid - update to 7.5
libecap-devel - update to 1.0.1-2.0.1
libecap - update to 1.0.1-2.0.1
squid - addressed in versions 4.9-26, 4.9-30, 6.6-8
squid-debuginfo - addressed in versions 4.9-26, 4.9-30, 6.6-8
squid-debugsource - addressed in versions 4.9-26, 4.9-30, 6.6-8
squid - update to 4.15-13
squid (Red Hat package) - addressed in versions 5.2-1.el9_0.10, 5.5-5.el9_2.11, 5.5-19.el9_6.3, 5.5-22.el9_7.4, 6.10-5.el10_0.2
squid (Ubuntu package) - addressed in versions 5.9-0ubuntu0.22.04.5, 6.14-0ubuntu0.24.04.2, 6.14-0ubuntu0.25.10.2
squid (Debian package) - update to 6.13-2+deb13u2
squid - addressed in versions 7.5-1.fc43, 7.5-1.fc44

External References

Related Security Bulletins