Important: squid:4 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:8317", "synopsis": "Important: squid:4 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for squid, libecap, module.libecap, module.squid.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Squid is a high-performance proxy caching server for web clients, supporting FTP, and HTTP data objects.\n\nSecurity Fix(es):\n\n* squid: Squid: Denial of Service via heap Use-After-Free vulnerability in ICP handling (CVE-2026-33526)\n\n* Squid: Squid: Denial of Service via crafted ICP traffic (CVE-2026-32748)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2451574", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2451574", "description": ""}, {"ticket": "2451577", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2451577", "description": ""}], "cves": [{"name": "CVE-2026-32748", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-32748", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-826"}, {"name": "CVE-2026-33526", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-33526", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-825"}], "references": [], "publishedAt": "2026-04-16T00:01:17.370160Z", "rpms": {"Rocky Linux 8": {"nvras": ["squid-7:4.15-10.module+el8.10.0+1928+e8441768.5.aarch64.rpm", "squid-7:4.15-10.module+el8.10.0+1885+e30b7122.3.aarch64.rpm","squid-7:4.15-10.module+el8.10.0+1881+7e31fb44.1.aarch64.rpm", "squid-7:4.15-10.module+el8.10.0+1758+80ba9f4b.aarch64.rpm", "squid-7:4.15-10.module+el8.10.0+1985+eaf982f0.6.aarch64.rpm", "squid-7:4.15-10.module+el8.10.0+1881+7e31fb44.1.x86_64.rpm", "squid-7:4.15-10.module+el8.10.0+1758+80ba9f4b.x86_64.rpm", "squid-7:4.15-10.module+el8.10.0+1885+e30b7122.3.x86_64.rpm", "squid-7:4.15-10.module+el8.10.0+1985+eaf982f0.6.x86_64.rpm", "squid-7:4.15-10.module+el8.10.0+1928+e8441768.5.x86_64.rpm", "libecap-0:1.0.1-2.module+el8.9.0+1437+df5ea8f0.aarch64.rpm", "libecap-0:1.0.1-2.module+el8.9.0+1437+df5ea8f0.src.rpm", "libecap-0:1.0.1-2.module+el8.9.0+1437+df5ea8f0.x86_64.rpm", "libecap-debuginfo-0:1.0.1-2.module+el8.9.0+1437+df5ea8f0.aarch64.rpm", "libecap-debuginfo-0:1.0.1-2.module+el8.9.0+1437+df5ea8f0.x86_64.rpm", "libecap-debugsource-0:1.0.1-2.module+el8.9.0+1437+df5ea8f0.aarch64.rpm", "libecap-debugsource-0:1.0.1-2.module+el8.9.0+1437+df5ea8f0.x86_64.rpm", "libecap-devel-0:1.0.1-2.module+el8.9.0+1437+df5ea8f0.aarch64.rpm", "libecap-devel-0:1.0.1-2.module+el8.9.0+1437+df5ea8f0.x86_64.rpm", "squid-7:4.15-10.module+el8.10.0+2080+49064dbd.9.aarch64.rpm", "squid-7:4.15-10.module+el8.10.0+1928+e8441768.5.src.rpm", "squid-7:4.15-10.module+el8.10.0+1985+eaf982f0.6.src.rpm", "squid-7:4.15-10.module+el8.10.0+1885+e30b7122.3.src.rpm", "squid-7:4.15-10.module+el8.10.0+2080+49064dbd.9.src.rpm", "squid-7:4.15-10.module+el8.10.0+1758+80ba9f4b.src.rpm", "squid-7:4.15-10.module+el8.10.0+1881+7e31fb44.1.src.rpm", "squid-7:4.15-10.module+el8.10.0+2080+49064dbd.9.x86_64.rpm", "squid-debuginfo-7:4.15-10.module+el8.10.0+1985+eaf982f0.6.aarch64.rpm", "squid-debuginfo-7:4.15-10.module+el8.10.0+1885+e30b7122.3.aarch64.rpm", "squid-debuginfo-7:4.15-10.module+el8.10.0+2080+49064dbd.9.aarch64.rpm", "squid-debuginfo-7:4.15-10.module+el8.10.0+1928+e8441768.5.aarch64.rpm", "squid-debuginfo-7:4.15-10.module+el8.10.0+1881+7e31fb44.1.aarch64.rpm", "squid-debuginfo-7:4.15-10.module+el8.10.0+1758+80ba9f4b.aarch64.rpm","squid-debuginfo-7:4.15-10.module+el8.10.0+2080+49064dbd.9.x86_64.rpm", "squid-debuginfo-7:4.15-10.module+el8.10.0+1758+80ba9f4b.x86_64.rpm", "squid-debuginfo-7:4.15-10.module+el8.10.0+1985+eaf982f0.6.x86_64.rpm", "squid-debuginfo-7:4.15-10.module+el8.10.0+1881+7e31fb44.1.x86_64.rpm", "squid-debuginfo-7:4.15-10.module+el8.10.0+1885+e30b7122.3.x86_64.rpm", "squid-debuginfo-7:4.15-10.module+el8.10.0+1928+e8441768.5.x86_64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+1928+e8441768.5.aarch64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+1985+eaf982f0.6.aarch64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+2080+49064dbd.9.aarch64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+1758+80ba9f4b.aarch64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+1881+7e31fb44.1.aarch64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+1885+e30b7122.3.aarch64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+1758+80ba9f4b.x86_64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+1881+7e31fb44.1.x86_64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+1985+eaf982f0.6.x86_64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+2080+49064dbd.9.x86_64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+1928+e8441768.5.x86_64.rpm", "squid-debugsource-7:4.15-10.module+el8.10.0+1885+e30b7122.3.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Address critical Denial of Service issues with squid on Rocky Linux. Important updates and fixes available now!. squid updates,Rocky Linux security,Denial of Service,security advisory. . Severity: Important. LinuxSecurity.com Team
Changes with Apache Traffic Server 9.2.9 #12071 - Fix chunked pipelined requests #12075 - Fix send 100 Continue optimization for GET #12077 - Fix intercept plugin ignoring ACL #12079 - ACL combination tests for 9.2.x. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-286e6fc13a 2025-03-14 02:12:06.905953+00:00 -------------------------------------------------------------------------------- Name : trafficserver Product : Fedora 40 Version : 9.2.9 Release : 1.fc40 URL : https://trafficserver.apache.org/ Summary : Fast, scalable and extensible HTTP/1.1 and HTTP/2 caching proxy server Description : Traffic Server is a high-performance building block for cloud services. It's more than just a caching proxy server; it also has support for plugins to build large scale web applications. Key features: Caching - Improve your response time, while reducing server load and bandwidth needs by caching and reusing frequently-requested web pages, images, and web service calls. Proxying - Easily add keep-alive, filter or anonymize content requests, or add load balancing by adding a proxy layer. Fast - Scales well on modern SMP hardware, handling 10s of thousands of requests per second. Extensible - APIs to write your own plug-ins to do anything from modifying HTTP headers to handling ESI requests to writing your own cache algorithm. Proven - Handling over 400TB a day at Yahoo! both as forward and reverse proxies, Apache Traffic Server is battle hardened. -------------------------------------------------------------------------------- Update Information: Changes with Apache Traffic Server 9.2.9 #12071 - Fix chunked pipelined requests #12075 - Fix send 100 Continue optimization for GET #12077 - Fix intercept plugin ignoring ACL #12079 - ACL combination tests for 9.2.x -------------------------------------------------------------------------------- ChangeLog: * WedMar 5 2025 Jered Floyd 9.2.9-1 - Update to upstream 9.2.9 - Resolves CVE-2024-38311, CVE-2024-56195, CVE-2024-56196, CVE-2024-56202 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-286e6fc13a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Several security vulnerabilities have been discovered in Squid, a full featured web proxy cache. Due to programming errors in Squid's HTTP request parsing, remote attackers may be able to execute a denial of service attack by sending large X-Forwarded-For header or trigger a stack buffer overflow while . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5637-1
It was discovered that the fix for CVE-2023-46846 was incomplete. In some cases Squid, a full featured web proxy cache, returned empty responses for URLs when Transfer-Encoding: chunked was in use. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3709-2
An update that solves 5 vulnerabilities and has three fixes is now available. . openSUSE Security Update: Security update for squid ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0879-1 Rating: important References: #1171164 #1171569 #1183436 #1185916 #1185918 #1185919 #1185921 #1185923 Cross-References: CVE-2020-25097 CVE-2021-28651 CVE-2021-28652 CVE-2021-28662 CVE-2021-31806 CVSS scores: CVE-2020-25097 (NVD) : 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N CVE-2020-25097 (SUSE): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N CVE-2021-28651 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-28651 (SUSE): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H CVE-2021-28652 (NVD) : 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H CVE-2021-28652 (SUSE): 6.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H CVE-2021-28662 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2021-28662 (SUSE): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2021-31806 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2021-31806 (SUSE): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that solves 5 vulnerabilities and has three fixes is now available. Description: This update for squid fixes the following issues: - update to 4.15: - CVE-2021-28652: Broken cache manager URL parsing (bsc#1185918) - CVE-2021-28651: Memory leak in RFC 2169 response parsing (bsc#1185921) - CVE-2021-28662: Limit HeaderLookupTable_t::lookup() to BadHdr and specific IDs (bsc#1185919) - CVE-2021-31806: Handle moreRange requests (bsc#1185916) - CVE-2020-25097: HTTP Request Smuggling vulnerability (bsc#1183436) - Handle more partial responses (bsc#1185923) - fix previous change to reinstante permissions macros, because the wrong path has been used (bsc#1171569). - use libexecdir instead of libdir to conform to recent changes in Factory (bsc#1171164). - Reinstate permissions macros for pinger binary, because the permissions package is also responsible for setting up the cap_net_raw capability, currently a fresh squid install doesn't get a capability bit at all (bsc#1171569). - Change pinger and basic_pam_auth helper to use standard permissions. pinger uses cap_net_raw=ep instead (bsc#1171569) This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-879=1 Package List: - openSUSE Leap 15.2 (x86_64): squid-4.15-lp152.2.9.1 squid-debuginfo-4.15-lp152.2.9.1 squid-debugsource-4.15-lp152.2.9.1 References: https://www.suse.com/security/cve/CVE-2020-25097.html https://www.suse.com/security/cve/CVE-2021-28651.html https://www.suse.com/security/cve/CVE-2021-28652.html https://www.suse.com/security/cve/CVE-2021-28662.html https://www.suse.com/security/cve/CVE-2021-31806.html https://bugzilla.suse.com/1171164 https://bugzilla.suse.com/1171569 https://bugzilla.suse.com/1183436 https://bugzilla.suse.com/1185916 https://bugzilla.suse.com/1185918 https://bugzilla.suse.com/1185919 https://bugzilla.suse.com/1185921 https://bugzilla.suse.com/1185923 . A crucial patch release for squid on openSUSE addresses various concerns and incorporates solutions for several security flaws.. openSUSE 15.2 Security Update, Squid MemoryLeak Fix, Important Squid Patch. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in Squid.. =========================================================================Ubuntu Security Notice USN-4356-1 May 13, 2020 squid, squid3 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 19.10 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Squid. Software Description: - squid: Web proxy cache server - squid3: Web proxy cache server Details: Jeriko One discovered that Squid incorrectly handled certain Edge Side Includes (ESI) responses. A malicious remote server could cause Squid to crash, possibly poison the cache, or possibly execute arbitrary code. (CVE-2019-12519, CVE-2019-12521) It was discovered that Squid incorrectly handled the hostname parameter to cachemgr.cgi when certain browsers are used. A remote attacker could possibly use this issue to inject HTML or invalid characters in the hostname parameter. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 19.10. (CVE-2019-18860) Clément Berthaux and Florian Guilbert discovered that Squid incorrectly handled Digest Authentication nonce values. A remote attacker could use this issue to replay nonce values, or possibly execute arbitrary code. (CVE-2020-11945) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: squid 4.10-1ubuntu1.1 Ubuntu 19.10: squid 4.8-1ubuntu2.3 Ubuntu 18.04 LTS: squid 3.5.27-1ubuntu1.6 Ubuntu 16.04 LTS: squid 3.5.12-1ubuntu7.11 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4356-1 CVE-2019-12519, CVE-2019-12521, CVE-2019-18860, CVE-2020-11945 PackageInformation: https://launchpad.net/ubuntu/+source/squid/4.10-1ubuntu1.1 https://launchpad.net/ubuntu/+source/squid/4.8-1ubuntu2.3 https://launchpad.net/ubuntu/+source/squid3/3.5.27-1ubuntu1.6 https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.11 . Multiple vulnerabilities addressed in Squid impacting Ubuntu LTS versions. It's advised to perform updates for enhanced system protection.. Squid Security, Ubuntu 20.04, Web Proxy Updates, Ubuntu Security Notices. . LinuxSecurity.com Team
Multiple vulnerabilities have been found in Squid, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202005-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Squid: Multiple vulnerabilities Date: May 12, 2020 Bugs: #719046 ID: 202005-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Squid, the worst of which could result in the arbitrary execution of code. Background ========= Squid is a full-featured Web proxy cache designed to run on Unix systems. It supports proxying and caching of HTTP, FTP, and other URLs, as well as SSL support, cache hierarchies, transparent caching, access control lists and many other features. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-proxy/squid < 4.11 > = 4.11 Description ========== Multiple vulnerabilities have been discovered in Squid. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Squid users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-proxy/squid-4.11" References ========= [ 1 ] CVE-2019-12519 https://nvd.nist.gov/vuln/detail/CVE-2019-12519 [ 2 ] CVE-2019-12521 https://nvd.nist.gov/vuln/detail/CVE-2019-12521 [ 3 ] CVE-2020-11945 https://nvd.nist.gov/vuln/detail/CVE-2020-11945 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202005-05 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been found in Squid, the worst of which could lead to arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202003-34 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Squid: Multiple vulnerabilities Date: March 16, 2020 Bugs: #699854, #708296 ID: 202003-34 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Squid, the worst of which could lead to arbitrary code execution. Background ========= Squid is a full-featured Web proxy cache designed to run on Unix systems. It supports proxying and caching of HTTP, FTP, and other URLs, as well as SSL support, cache hierarchies, transparent caching, access control lists and many other features. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-proxy/squid < 4.10 > = 4.10 Description ========== Multiple vulnerabilities have been discovered in Squid. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker, by sending a specially crafted request, could possibly execute arbitrary code with the privileges of the process, obtain sensitive information or cause a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All Squid users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-proxy/squid-4.10" References ========= [ 1 ] CVE-2019-12526 https://nvd.nist.gov/vuln/detail/CVE-2019-12526 [ 2 ] CVE-2019-12528 https://nvd.nist.gov/vuln/detail/CVE-2019-12528 [ 3 ] CVE-2019-18678 https://nvd.nist.gov/vuln/detail/CVE-2019-18678 [ 4 ] CVE-2019-18679 https://nvd.nist.gov/vuln/detail/CVE-2019-18679 [ 5 ] CVE-2020-8449 https://nvd.nist.gov/vuln/detail/CVE-2020-8449 [ 6 ] CVE-2020-8450 https://nvd.nist.gov/vuln/detail/CVE-2020-8450 [ 7 ] CVE-2020-8517 https://nvd.nist.gov/vuln/detail/CVE-2020-8517 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202003-34 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.