ALAS2023-2026-3145


Amazon Linux 2023 Security Advisory: ALAS2023-2026-3145
Advisory Released Date: 2026-09-29
Advisory Updated Date: 2026-09-29
Severity: Important

Issue Overview:

Due to a CWE-841 Improper Enforcement of Behavioral Workflow
bug Squid is vulnerable to a Request Smuggling attack against
HTTP/1.1 Transfer-Encoding.

This problem allows a trusted client to perform an HTTP Request
Smuggling attack when HTTP/1.1 is used. Bypassing security
mechanisms that may be in place between attacker and Squid.

When there is an HTTP cache operating prior to the affected
Squid, this Request Smuggling attack also allows the attacker
to poison that web cache and store arbitrary malicious content
at any URL for delivery to other clients future requests. (CVE-2026-61642)


Affected Packages:

squid


Issue Correction:
Run dnf update squid --releasever 2023.12.20260928 or dnf update --advisory ALAS2023-2026-3145 --releasever 2023.12.20260928 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    squid-debuginfo-6.13-1.amzn2023.0.6.aarch64
    squid-debugsource-6.13-1.amzn2023.0.6.aarch64
    squid-6.13-1.amzn2023.0.6.aarch64

src:
    squid-6.13-1.amzn2023.0.6.src

x86_64:
    squid-debuginfo-6.13-1.amzn2023.0.6.x86_64
    squid-debugsource-6.13-1.amzn2023.0.6.x86_64
    squid-6.13-1.amzn2023.0.6.x86_64