Amazon Linux 2023 Security Advisory: ALAS2023-2026-3145
Advisory Released Date: 2026-09-29
Advisory Updated Date: 2026-09-29
Due to a CWE-841 Improper Enforcement of Behavioral Workflow
bug Squid is vulnerable to a Request Smuggling attack against
HTTP/1.1 Transfer-Encoding.
This problem allows a trusted client to perform an HTTP Request
Smuggling attack when HTTP/1.1 is used. Bypassing security
mechanisms that may be in place between attacker and Squid.
When there is an HTTP cache operating prior to the affected
Squid, this Request Smuggling attack also allows the attacker
to poison that web cache and store arbitrary malicious content
at any URL for delivery to other clients future requests. (CVE-2026-61642)
Affected Packages:
squid
Issue Correction:
Run dnf update squid --releasever 2023.12.20260928 or dnf update --advisory ALAS2023-2026-3145 --releasever 2023.12.20260928 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
aarch64:
squid-debuginfo-6.13-1.amzn2023.0.6.aarch64
squid-debugsource-6.13-1.amzn2023.0.6.aarch64
squid-6.13-1.amzn2023.0.6.aarch64
src:
squid-6.13-1.amzn2023.0.6.src
x86_64:
squid-debuginfo-6.13-1.amzn2023.0.6.x86_64
squid-debugsource-6.13-1.amzn2023.0.6.x86_64
squid-6.13-1.amzn2023.0.6.x86_64