Use After Free in Squid - CVE-2026-32748
Published: March 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in ICP request handling when processing ICP traffic. A remote attacker can send a specially crafted ICP request to cause a denial of service.
The vulnerability is only exploitable on Squid deployments that have ICP support enabled via a non-zero icp_port configuration.
Affected software
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Ubuntu
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libecap-devel
libecap
squid
squid (Red Hat package)
squid (Ubuntu package)
squid-debugsource
squid-debuginfo
How to mitigate CVE-2026-32748
libecap-devel - update to 1.0.1-2.0.1
libecap - update to 1.0.1-2.0.1
squid - update to 4.15-13
squid (Red Hat package) - addressed in versions 5.2-1.el9_0.10, 5.5-5.el9_2.11, 5.5-19.el9_6.3, 5.5-22.el9_7.4, 6.10-5.el10_0.2
squid (Ubuntu package) - addressed in versions 5.9-0ubuntu0.22.04.5, 6.14-0ubuntu0.24.04.2, 6.14-0ubuntu0.25.10.2
squid - update to 6.6-8
squid-debugsource - update to 6.6-8
squid-debuginfo - update to 6.6-8
squid - addressed in versions 7.5-1.fc43, 7.5-1.fc44
External References
Related Security Bulletins
- Multiple vulnerabilities in Squid ICP feature
- Red Hat Enterprise Linux 9 update for squid
- openEuler 24.03 LTS update for squid
- openEuler 24.03 LTS SP3 update for squid
- openEuler 24.03 LTS SP2 update for squid
- openEuler 24.03 LTS SP1 update for squid
- Ubuntu update for squid
- Red Hat Enterprise Linux 8 update for the squid:4 module
- Red Hat Enterprise Linux 9 update for squid
- Red Hat Enterprise Linux 9 update for squid
- Red Hat Enterprise Linux 9 update for squid
- Anolis OS update for squid:4 module
- Fedora 43 update for squid
- Fedora 44 update for squid
- Red Hat Enterprise Linux 10 update for squid
- Red Hat Enterprise Linux 8 update for the squid:4 module
- Red Hat Enterprise Linux 8 update for the squid:4 module
- Red Hat Enterprise Linux 8 update for the squid:4 module