CVE-2026-50012
Publication date 12 June 2026
Last updated 7 August 2026
Ubuntu priority
Cvss 3 Severity Score
Description
Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in src/peer_digest.cc), Squid is vulnerable to a heap-based buffer overflow: a cache digest's on-the-wire size may be larger than the mask_size declared within the digest, so a trusted peer sending a maliciously crafted reply to a cache_digest request message can trigger the overflow. This attack is limited to Squid instances compiled with the --enable-cache-digests option and configured with cache_peer entries. This issue is fixed in version 7.6.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| squid | 26.04 LTS resolute |
Fixed 7.2-2ubuntu2.2
|
| 24.04 LTS noble |
Fixed 6.14-0ubuntu0.24.04.4
|
|
| 22.04 LTS jammy |
Fixed 5.9-0ubuntu0.22.04.7
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| squid3 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
Severity score breakdown
CVSS version: CVSS v3.0
Base score
5.5 · Medium
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H