High severity7.5NVD Advisory· Published Nov 3, 2023· Updated Jun 17, 2026
CVE-2023-5824
CVE-2023-5824
Description
A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
20- osv-coords4 versionspkg:rpm/almalinux/libecap-develpkg:rpm/opensuse/squid&distro=openSUSE%20Tumbleweedpkg:rpm/almalinux/squidpkg:rpm/almalinux/libecap
< 1.0.1-2.module_el8.6.0+2741+01592ae8+ 3 more
- (no CPE)range: < 1.0.1-2.module_el8.6.0+2741+01592ae8
- (no CPE)range: < 6.4-1.1
- (no CPE)range: < 7:5.5-6.el9_3.2
- (no CPE)range: < 1.0.1-2.module_el8.6.0+2741+01592ae8
- Red Hat/Red Hat Enterprise Linux 8.6 Extended Update Supportv5cpe:/a:redhat:rhel_eus:8.6::appstreamRange: 8060020231222131040.ad008a3a
- Red Hat/Red Hat Enterprise Linux 8.8 Extended Update Supportv5cpe:/a:redhat:rhel_eus:8.8::appstreamRange: 8080020231222130009.63b34585
- Red Hat/Red Hat Enterprise Linux 9.0 Extended Update Supportv5cpe:/a:redhat:rhel_eus:9.0::appstreamRange: 7:5.2-1.el9_0.4
- Red Hat/Red Hat Enterprise Linux 9.2 Extended Update Supportv5cpe:/a:redhat:rhel_eus:9.2::appstreamRange: 7:5.5-5.el9_2.3
cpe:/a:redhat:rhel_tus:8.2::appstream+ 1 more
- cpe:/a:redhat:rhel_tus:8.2::appstreamrange: 8020020240122164331.4cda2c84
- cpe:/a:redhat:rhel_e4s:8.4::appstreamrange: 8040020240122165847.522a0ee4
cpe:/a:redhat:enterprise_linux:8::appstream+ 7 more
- cpe:/a:redhat:enterprise_linux:8::appstreamrange: 8090020231130092412.a75119d5
- cpe:/a:redhat:enterprise_linux:9::appstreamrange: 7:5.5-6.el9_3.2
- cpe:/o:redhat:enterprise_linux:6
- cpe:/o:redhat:enterprise_linux:7
- cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
13- access.redhat.com/security/cve/CVE-2023-5824nvdThird Party Advisory
- github.com/squid-cache/squid/security/advisories/GHSA-543m-w2m2-g255nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue Tracking
- access.redhat.com/errata/RHSA-2023:7465nvd
- access.redhat.com/errata/RHSA-2023:7668nvd
- access.redhat.com/errata/RHSA-2024:0072nvd
- access.redhat.com/errata/RHSA-2024:0397nvd
- access.redhat.com/errata/RHSA-2024:0771nvd
- access.redhat.com/errata/RHSA-2024:0772nvd
- access.redhat.com/errata/RHSA-2024:0773nvd
- access.redhat.com/errata/RHSA-2024:1153nvd
- lists.debian.org/debian-lts-announce/2025/09/msg00027.htmlnvd
- security.netapp.com/advisory/ntap-20231130-0003/nvd
News mentions
0No linked articles in our index yet.