Use After Free in Squid - CVE-2026-32748

 

Use After Free in Squid - CVE-2026-32748

Published: March 25, 2026


Vulnerability identifier: #VU124612
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-32748
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use-after-free in ICP request handling when processing ICP traffic. A remote attacker can send a specially crafted ICP request to cause a denial of service.

The vulnerability is only exploitable on Squid deployments that have ICP support enabled via a non-zero icp_port configuration.


Affected software

Squid
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Ubuntu
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libecap-devel
libecap
squid
squid (Red Hat package)
squid (Ubuntu package)
squid-debugsource
squid-debuginfo

How to mitigate CVE-2026-32748

Install security update from vendor's website.

Squid - update to 7.5
libecap-devel - update to 1.0.1-2.0.1
libecap - update to 1.0.1-2.0.1
squid - update to 4.15-13
squid (Red Hat package) - addressed in versions 5.2-1.el9_0.10, 5.5-5.el9_2.11, 5.5-19.el9_6.3, 5.5-22.el9_7.4, 6.10-5.el10_0.2
squid (Ubuntu package) - addressed in versions 5.9-0ubuntu0.22.04.5, 6.14-0ubuntu0.24.04.2, 6.14-0ubuntu0.25.10.2
squid - update to 6.6-8
squid-debugsource - update to 6.6-8
squid-debuginfo - update to 6.6-8
squid - addressed in versions 7.5-1.fc43, 7.5-1.fc44

External References

Related Security Bulletins