[ubuntu/jammy-security] squid 5.9-0ubuntu0.22.04.5 (Accepted)
Marc Deslauriers
marc.deslauriers at canonical.com
Wed Apr 8 12:32:26 UTC 2026
squid (5.9-0ubuntu0.22.04.5) jammy-security; urgency=medium
* SECURITY UPDATE: use-after-free via ICP protocol
- debian/patches/CVE-2026-32748.patch: fix HttpRequest lifetime for ICP
v3 queries in src/ICP.h, src/icp_v2.cc, src/icp_v3.cc,
src/tests/stub_icp.cc.
- CVE-2026-32748
* SECURITY UPDATE: out-of-bounds read via ICP protocol
- debian/patches/CVE-2026-33515.patch: fix validation of packet sizes
and URLs in src/ICP.h, src/icp_v2.cc, src/icp_v3.cc,
src/tests/stub_icp.cc.
- CVE-2026-33515
* SECURITY UPDATE: use-after-free via ICP protocol
- debian/patches/CVE-2026-33526.patch: do not escape malformed URI
twice when sending ICP errors in src/icp_v2.cc.
- CVE-2026-33526
Date: 2026-04-02 19:54:24.493080+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/squid/5.9-0ubuntu0.22.04.5
-------------- next part --------------
Sorry, changesfile not available.
More information about the jammy-changes
mailing list