CVE-2020-24606: High severity IBM Security Guardium vulnerability
Last updated 25 August 2025
Other sources
Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cachepeer is used with the cache digests feature. The problem exists because peerDigestHandleReply() livelocking in peerdigest.cc mishandles EOF.
— Launchpad
Squid is vulnerable to a denial of service, caused by the mishandling of EOF in the peerDigestHandleReply function in peerdigest.cc. By sending a specially-crafted Cache Digest response message, a remote attacker could exploit this vulnerability to consume all available CPU cycles.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-24606?
CVE-2020-24606 is a vulnerability in Squid, a cache proxy server, that allows a trusted peer to perform a Denial of Service attack by consuming all available CPU cycles.
Which versions of Squid are affected by CVE-2020-24606?
Squid versions before 4.13 and 5.x before 5.0.4 are affected by CVE-2020-24606.
How severe is CVE-2020-24606?
CVE-2020-24606 has a severity rating of 8.6 (high).
What is the recommended fix for CVE-2020-24606?
To fix CVE-2020-24606, it is recommended to update Squid to version 4.13 or 5.0.4 or later.
Where can I find more information about CVE-2020-24606?
More information about CVE-2020-24606 can be found on the official Squid website and the OpenSUSE security announcements.