Out-of-bounds read in Squid - CVE-2026-33515
Published: March 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper input validation in ICP message handling when processing ICP traffic. A remote attacker can send a specially crafted ICP request to disclose small amounts of memory potentially containing sensitive information.
The attack is limited to Squid deployments that explicitly enable ICP support (i.e., configure a non-zero icp_port).
Affected software
Debian Linux
openEuler
Ubuntu
squid
squid-debuginfo
squid-debugsource
squid (Ubuntu package)
squid (Debian package)
How to mitigate CVE-2026-33515
squid - addressed in versions 4.9-26, 4.9-30, 6.6-8
squid-debuginfo - addressed in versions 4.9-26, 4.9-30, 6.6-8
squid-debugsource - addressed in versions 4.9-26, 4.9-30, 6.6-8
squid (Ubuntu package) - addressed in versions 5.9-0ubuntu0.22.04.5, 6.14-0ubuntu0.24.04.2, 6.14-0ubuntu0.25.10.2
squid (Debian package) - update to 6.13-2+deb13u2
External References
Related Security Bulletins
- Multiple vulnerabilities in Squid ICP feature
- openEuler 24.03 LTS update for squid
- openEuler 22.03 LTS SP4 update for squid
- openEuler 20.03 LTS SP4 update for squid
- openEuler 24.03 LTS SP3 update for squid
- openEuler 24.03 LTS SP2 update for squid
- openEuler 24.03 LTS SP1 update for squid
- Ubuntu update for squid
- Debian update for squid