[ubuntu/questing-security] squid 6.14-0ubuntu0.25.10.2 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Wed Apr 8 12:32:19 UTC 2026


squid (6.14-0ubuntu0.25.10.2) questing-security; urgency=medium

  * SECURITY UPDATE: use-after-free via ICP protocol
    - debian/patches/CVE-2026-32748.patch: fix HttpRequest lifetime for ICP
      v3 queries in src/ICP.h, src/icp_v2.cc, src/icp_v3.cc,
      src/tests/stub_icp.cc.
    - CVE-2026-32748
  * SECURITY UPDATE: out-of-bounds read via ICP protocol
    - debian/patches/CVE-2026-33515.patch: fix validation of packet sizes
      and URLs in src/ICP.h, src/icp_v2.cc, src/icp_v3.cc,
      src/tests/stub_icp.cc.
    - CVE-2026-33515
  * SECURITY UPDATE: use-after-free via ICP protocol
    - debian/patches/CVE-2026-33526.patch: do not escape malformed URI
      twice when sending ICP errors in src/icp_v2.cc.
    - CVE-2026-33526

squid (6.14-0ubuntu0.25.10.1) questing; urgency=medium

  * New upstream release 6.14 (LP: #2127669)
    - Do not get stuck in RESPMOD after pausing peer read(2)
    - Fix "make check" linking on Solaris
    - Fix SNMP cacheNumObjCount -- number of cached objects
    - Do not duplicate received Surrogate-Capability in sent requests
    - Fix Mem::Segment::open() stub to fix build without shm_open()
    - CI and documentation updates

Date: 2026-04-02 18:36:11.923520+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/squid/6.14-0ubuntu0.25.10.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the Questing-changes mailing list