[ubuntu/questing-security] squid 6.14-0ubuntu0.25.10.2 (Accepted)
Marc Deslauriers
marc.deslauriers at canonical.com
Wed Apr 8 12:32:19 UTC 2026
squid (6.14-0ubuntu0.25.10.2) questing-security; urgency=medium
* SECURITY UPDATE: use-after-free via ICP protocol
- debian/patches/CVE-2026-32748.patch: fix HttpRequest lifetime for ICP
v3 queries in src/ICP.h, src/icp_v2.cc, src/icp_v3.cc,
src/tests/stub_icp.cc.
- CVE-2026-32748
* SECURITY UPDATE: out-of-bounds read via ICP protocol
- debian/patches/CVE-2026-33515.patch: fix validation of packet sizes
and URLs in src/ICP.h, src/icp_v2.cc, src/icp_v3.cc,
src/tests/stub_icp.cc.
- CVE-2026-33515
* SECURITY UPDATE: use-after-free via ICP protocol
- debian/patches/CVE-2026-33526.patch: do not escape malformed URI
twice when sending ICP errors in src/icp_v2.cc.
- CVE-2026-33526
squid (6.14-0ubuntu0.25.10.1) questing; urgency=medium
* New upstream release 6.14 (LP: #2127669)
- Do not get stuck in RESPMOD after pausing peer read(2)
- Fix "make check" linking on Solaris
- Fix SNMP cacheNumObjCount -- number of cached objects
- Do not duplicate received Surrogate-Capability in sent requests
- Fix Mem::Segment::open() stub to fix build without shm_open()
- CI and documentation updates
Date: 2026-04-02 18:36:11.923520+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/squid/6.14-0ubuntu0.25.10.2
-------------- next part --------------
Sorry, changesfile not available.
More information about the Questing-changes
mailing list