Hi Amos,

Thank you for bringing these 3 issues/advisories to oss-security.

On Wed, Mar 25, 2026 at 05:20:11PM +1300, Amos Jeffries wrote:
>  Due to a heap Use-After-Free bug Squid is vulnerable to Denial
>  of Service when handling ICP traffic.

Since use-after-free bugs commonly allow for impact not limited to DoS,
but often also code execution and/or information leak, it would help if
you provide justification why you claim this is just a DoS - or add
wording that it may be more than just a DoS.  Ditto for SQUID-2026:2
(CVE-2026-32748).

Thanks,

Alexander

Reply via email to