Impact
Prior to version 7.6, Squid’s cache digest reply handling suffered from an improper input validation bug (peerDigestSwapInMask in src/peer_digest.cc). This bug causes a heap‑based buffer overflow when a trusted peer sends a maliciously crafted cache_digest reply message: the cache digest’s on‑the‑wire size may exceed the mask_size declared within the digest. The flaw can be exercised only when Squid is compiled with the --enable-cache-digests option, and it leads to a crash of the Squid process, resulting in denial of service. The vulnerability is identified as CWE‑122 and CWE‑20.
Affected Systems
Squid caching proxy server versions prior to 7.6 that are compiled with the --enable-cache-digests option and configured with cache_peer entries are vulnerable. Any installation running an unpatched version that processes cache_digest replies can be exposed.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score of 1% suggests a low but nonzero probability of exploitation, and the issue is not listed in the CISA KEV catalog, which also indicates limited evidence of exploitation in the wild. The attacker must be a trusted server within the network, able to send crafted cache_digest replies to the vulnerable Squid instance. Successful exploitation would be internal or hybrid, causing a service disruption of the proxy.
OpenCVE Enrichment
Debian DLA
Debian DSA