Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero `icp_port`). This problem _cannot_ be mitigated by denying ICP queries using `icp_access` rules. This bug is fixed in Squid version 7.5.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:6301 https://access.redhat.com/errata/RHSA-2026:6301
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:8119 https://access.redhat.com/errata/RHSA-2026:8119
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:8317 https://access.redhat.com/errata/RHSA-2026:8317
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:8880 https://access.redhat.com/errata/RHSA-2026:8880
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:9220 https://access.redhat.com/errata/RHSA-2026:9220
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:10257 https://access.redhat.com/errata/RHSA-2026:10257
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:10256 https://access.redhat.com/errata/RHSA-2026:10256
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:10255 https://access.redhat.com/errata/RHSA-2026:10255
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:11901 https://access.redhat.com/errata/RHSA-2026:11901