Back

HIGH

Squid has Denial of Service in ICP Response handling

Published Mar 26, 2026

Description

Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero `icp_port`). This problem _cannot_ be mitigated by denying ICP queries using `icp_access` rules. This bug is fixed in Squid version 7.5.

Affected products

Remediation

Red Hat statement

This Important flaw in Squid can lead to a Denial of Service when processing specially crafted Internet Cache Protocol (ICP) traffic. This vulnerability affects Red Hat products running Squid if ICP support is explicitly enabled by configuring a non-zero `icp_port`. Deployments where ICP is not enabled by default are not affected.

Red Hat mitigation

To mitigate this issue, ensure that ICP support is not explicitly enabled in the Squid configuration. This can be achieved by commenting out or setting `icp_port` to `0` in the `squid.conf` file. After modifying the configuration, the Squid service must be reloaded or restarted for the changes to take effect. Example: ``` # icp_port 3130 ``` or ``` icp_port 0 ``` Warning: Reloading or restarting the Squid service may temporarily interrupt proxy services.

Metrics

References (20)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Mar 26, 2026
Updated Jul 15, 2026
Reserved Mar 13, 2026
CISA Vulnrichment
Updated Mar 26, 2026
NVD
Status Modified
Modified Jul 15, 2026
Red Hat
Severity Important
Public date Mar 26, 2026