Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:9644 - Security Advisory
Issued:
2024-11-14
Updated:
2024-11-14

RHSA-2024:9644 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: squid:4 security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for the squid:4 module is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects.

Security Fix(es):

  • squid: vulnerable to a Denial of Service attack against Cache Manager error responses (CVE-2024-23638)
  • squid: Denial of Service processing ESI response content (CVE-2024-45802)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64

Fixes

  • BZ - 2260051 - CVE-2024-23638 squid: vulnerable to a Denial of Service attack against Cache Manager error responses
  • BZ - 2322154 - CVE-2024-45802 squid: Denial of Service processing ESI response content

CVEs

  • CVE-2024-23638
  • CVE-2024-45802

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
libecap-1.0.1-2.module+el8.9.0+19703+a1da7223.src.rpm SHA-256: 68456b844f86281a4db4053345c0704bea4293018ca2cd394f979ba8cd263cb4
squid-4.15-10.module+el8.10.0+22489+b920747d.3.src.rpm SHA-256: 2ee75eac5c91b69f50574146a6c201e7690dda24be4ddc9acd3ec6fbb48a2571
x86_64
libecap-1.0.1-2.module+el8.9.0+19703+a1da7223.x86_64.rpm SHA-256: 40d43cf013f21f97631fb8470285164a523071f7882f748663494c0f1625b427
libecap-debuginfo-1.0.1-2.module+el8.9.0+19703+a1da7223.x86_64.rpm SHA-256: 6e683c898b1c714b9485a0acb012d0e5b71ddb75514cf6a37ee472ad6c373bd9
libecap-debugsource-1.0.1-2.module+el8.9.0+19703+a1da7223.x86_64.rpm SHA-256: f9d480af68e77827a9e84e1cdc2b9d48fefda63dceec87b54114568520ba6ca7
libecap-devel-1.0.1-2.module+el8.9.0+19703+a1da7223.x86_64.rpm SHA-256: 11b5623fb94967adf20000120212bb87d5e0485c1a4d17ccaeea54bf45abeaca
squid-4.15-10.module+el8.10.0+22489+b920747d.3.x86_64.rpm SHA-256: 9a8aa36184d891754bff214f8ed11157fc9110358b5333a889aaaa6c2a24e5cf
squid-debuginfo-4.15-10.module+el8.10.0+22489+b920747d.3.x86_64.rpm SHA-256: 711fd19bbde530ebb82d9bb1a164ffc7158aff08017df531f80c56b7dcdc0a8f
squid-debugsource-4.15-10.module+el8.10.0+22489+b920747d.3.x86_64.rpm SHA-256: b9411490be063fac8754e01d4062de12793042388a9fff3c7074ccc481bb62d2

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
libecap-1.0.1-2.module+el8.9.0+19703+a1da7223.src.rpm SHA-256: 68456b844f86281a4db4053345c0704bea4293018ca2cd394f979ba8cd263cb4
squid-4.15-10.module+el8.10.0+22489+b920747d.3.src.rpm SHA-256: 2ee75eac5c91b69f50574146a6c201e7690dda24be4ddc9acd3ec6fbb48a2571
s390x
libecap-1.0.1-2.module+el8.9.0+19703+a1da7223.s390x.rpm SHA-256: 7b177d330230a2a8637f1f46c83e52796fc981f307861cd5ac4e4ff46759a6a3
libecap-debuginfo-1.0.1-2.module+el8.9.0+19703+a1da7223.s390x.rpm SHA-256: cdaadf99ef98a02d12f5047e680e5f40c71f7a2df68e2808343242f0a37bf76d
libecap-debugsource-1.0.1-2.module+el8.9.0+19703+a1da7223.s390x.rpm SHA-256: 24efacc784d597f773c9856ed0ed99d78f9c0b9ece1b84de60cef147298e9c01
libecap-devel-1.0.1-2.module+el8.9.0+19703+a1da7223.s390x.rpm SHA-256: e7d1d34aaeb21d0dbcb11af624315ecd47b7d7b644edd52ea09f0f0614bb6f54
squid-4.15-10.module+el8.10.0+22489+b920747d.3.s390x.rpm SHA-256: 9e5b20dae01248df36cf8d5ff54a7808274354e751b59e8fa0ea5d79971283d3
squid-debuginfo-4.15-10.module+el8.10.0+22489+b920747d.3.s390x.rpm SHA-256: e4e0c996c3832012c9c2ed46ba90af04922cf96b361cb9ae1ceb12b1b013033f
squid-debugsource-4.15-10.module+el8.10.0+22489+b920747d.3.s390x.rpm SHA-256: 12ba21f61012e42bdabc25fbf5a75f7963c17b546af117f3292812d14a7508e4

Red Hat Enterprise Linux for Power, little endian 8

SRPM
libecap-1.0.1-2.module+el8.9.0+19703+a1da7223.src.rpm SHA-256: 68456b844f86281a4db4053345c0704bea4293018ca2cd394f979ba8cd263cb4
squid-4.15-10.module+el8.10.0+22489+b920747d.3.src.rpm SHA-256: 2ee75eac5c91b69f50574146a6c201e7690dda24be4ddc9acd3ec6fbb48a2571
ppc64le
libecap-1.0.1-2.module+el8.9.0+19703+a1da7223.ppc64le.rpm SHA-256: 779f161dd569dae1700e0acfd9169bd55763db01ad3112207fbcd49716bfd58f
libecap-debuginfo-1.0.1-2.module+el8.9.0+19703+a1da7223.ppc64le.rpm SHA-256: 6720c36ff829fc1b8004458fb08001f1fd8b3a40bdd57e418543a3b890421129
libecap-debugsource-1.0.1-2.module+el8.9.0+19703+a1da7223.ppc64le.rpm SHA-256: 8120cedcc13b839d73ed203a89ebbfe1803579e0549be7ae5adab0976f1fe0de
libecap-devel-1.0.1-2.module+el8.9.0+19703+a1da7223.ppc64le.rpm SHA-256: fe6d7e62eb8f5eb30ccd717c5c46cc9c1f6388b158515d25149d259bf30e7737
squid-4.15-10.module+el8.10.0+22489+b920747d.3.ppc64le.rpm SHA-256: ef097da83477fd3126443f4c6a466a36eb89187fdd17d46c7164e77c6dbcb726
squid-debuginfo-4.15-10.module+el8.10.0+22489+b920747d.3.ppc64le.rpm SHA-256: eb9621a04289ec1488aaa595dca0e3089cbe284382991d8fd68360038b1cf363
squid-debugsource-4.15-10.module+el8.10.0+22489+b920747d.3.ppc64le.rpm SHA-256: 8b1e83cb55903b3f2774c21e7e9e16e1c4c43dcd623496d3f532b14b28eab10e

Red Hat Enterprise Linux for ARM 64 8

SRPM
libecap-1.0.1-2.module+el8.9.0+19703+a1da7223.src.rpm SHA-256: 68456b844f86281a4db4053345c0704bea4293018ca2cd394f979ba8cd263cb4
squid-4.15-10.module+el8.10.0+22489+b920747d.3.src.rpm SHA-256: 2ee75eac5c91b69f50574146a6c201e7690dda24be4ddc9acd3ec6fbb48a2571
aarch64
libecap-1.0.1-2.module+el8.9.0+19703+a1da7223.aarch64.rpm SHA-256: 32b30079509b8d16ed9e85fb0ed15c0e2a8efae115f9fd5622219b65d2363db8
libecap-debuginfo-1.0.1-2.module+el8.9.0+19703+a1da7223.aarch64.rpm SHA-256: 72b65db7b4a0220a8185e142c1fc8e2c56480b05028a924138ea24d1ce90b3dd
libecap-debugsource-1.0.1-2.module+el8.9.0+19703+a1da7223.aarch64.rpm SHA-256: d408408456d44c98da25fb4dc3dbd7de545b3ffa6de8527bd7598a366a7012a3
libecap-devel-1.0.1-2.module+el8.9.0+19703+a1da7223.aarch64.rpm SHA-256: 0b78af9f6df4a8580f41145718d3f5b0d52bf566bdc6fed26b2ed8c8140f42bc
squid-4.15-10.module+el8.10.0+22489+b920747d.3.aarch64.rpm SHA-256: 9e0483279d48c8714b1ea2d35571969edb3559a6fb74ce0c8af473f49397a34f
squid-debuginfo-4.15-10.module+el8.10.0+22489+b920747d.3.aarch64.rpm SHA-256: 961787c2b56d7ab598bc27725cbe69c72b6dd91be203d4a0f78e3abab9a88325
squid-debugsource-4.15-10.module+el8.10.0+22489+b920747d.3.aarch64.rpm SHA-256: 0bb6570c6e87df89677a079bce63117917e7aff825b9487526d868a1ba62b2c5

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility