RHSA-2026:20564HighCVSS 7.5

Red Hat Security Advisory: squid:4 security update

Published
May 26, 2026
Last Modified
October 2, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-32748 — Squid: Squid: Denial of Service via crafted ICP traffic CVE-2026-33526 — squid: Squid: Denial of Service via heap Use-After-Free vulnerability in ICP handling

🎯 Affected products20

  • Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
  • libecap-0:1.0.1-2.module+el8.1.0+4044+36416a77.src (squid:4) as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • libecap-0:1.0.1-2.module+el8.1.0+4044+36416a77.src (squid:4) as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
  • libecap-0:1.0.1-2.module+el8.1.0+4044+36416a77.x86_64 (squid:4) as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • libecap-0:1.0.1-2.module+el8.1.0+4044+36416a77.x86_64 (squid:4) as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
  • libecap-debuginfo-0:1.0.1-2.module+el8.1.0+4044+36416a77.x86_64 (squid:4) as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • libecap-debuginfo-0:1.0.1-2.module+el8.1.0+4044+36416a77.x86_64 (squid:4) as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
  • libecap-debugsource-0:1.0.1-2.module+el8.1.0+4044+36416a77.x86_64 (squid:4) as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • libecap-debugsource-0:1.0.1-2.module+el8.1.0+4044+36416a77.x86_64 (squid:4) as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
  • libecap-devel-0:1.0.1-2.module+el8.1.0+4044+36416a77.x86_64 (squid:4) as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • libecap-devel-0:1.0.1-2.module+el8.1.0+4044+36416a77.x86_64 (squid:4) as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
  • squid-7:4.11-4.module+el8.4.0+24287+ae9ea41b.11.src (squid:4) as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • squid-7:4.11-4.module+el8.4.0+24287+ae9ea41b.11.src (squid:4) as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
  • squid-7:4.11-4.module+el8.4.0+24287+ae9ea41b.11.x86_64 (squid:4) as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • squid-7:4.11-4.module+el8.4.0+24287+ae9ea41b.11.x86_64 (squid:4) as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
  • squid-debuginfo-7:4.11-4.module+el8.4.0+24287+ae9ea41b.11.x86_64 (squid:4) as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • squid-debuginfo-7:4.11-4.module+el8.4.0+24287+ae9ea41b.11.x86_64 (squid:4) as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
  • squid-debugsource-7:4.11-4.module+el8.4.0+24287+ae9ea41b.11.x86_64 (squid:4) as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • squid-debugsource-7:4.11-4.module+el8.4.0+24287+ae9ea41b.11.x86_64 (squid:4) as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, ensure that ICP support is not explicitly enabled in the Squid configuration. This can be achieved by commenting out or setting `icp_port` to `0` in the `squid.conf` file. After modifying the configuration, the Squid service must be reloaded or restarted for the changes to take effect. Example: ``` # icp_port 3130 ``` or ``` icp_port 0 ``` Warning: Reloading or restarting the Squid service may temporarily interrupt proxy services. Workaround: To mitigate this issue, disable ICP support in Squid by ensuring that `icp_port` is set to `0` in the `squid.conf` configuration file. This will prevent Squid from processing ICP traffic and eliminate the attack vector. After modifying the configuration, the Squid service must be restarted for the changes to take effect.

🔗 References (5)