[ubuntu/jammy-security] squid 5.9-0ubuntu0.22.04.5 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Wed Apr 8 12:32:26 UTC 2026


squid (5.9-0ubuntu0.22.04.5) jammy-security; urgency=medium

  * SECURITY UPDATE: use-after-free via ICP protocol
    - debian/patches/CVE-2026-32748.patch: fix HttpRequest lifetime for ICP
      v3 queries in src/ICP.h, src/icp_v2.cc, src/icp_v3.cc,
      src/tests/stub_icp.cc.
    - CVE-2026-32748
  * SECURITY UPDATE: out-of-bounds read via ICP protocol
    - debian/patches/CVE-2026-33515.patch: fix validation of packet sizes
      and URLs in src/ICP.h, src/icp_v2.cc, src/icp_v3.cc,
      src/tests/stub_icp.cc.
    - CVE-2026-33515
  * SECURITY UPDATE: use-after-free via ICP protocol
    - debian/patches/CVE-2026-33526.patch: do not escape malformed URI
      twice when sending ICP errors in src/icp_v2.cc.
    - CVE-2026-33526

Date: 2026-04-02 19:54:24.493080+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/squid/5.9-0ubuntu0.22.04.5
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list