CVE-2023-46847: Red Hat Enterprise Linux

High severity, CVSS 7.5. EPSS: 88.4% chance of exploitation in the next 30 days.

Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.

Affected products

  • Red Hat Enterprise Linux: version 8.0 only; version 9.0 only
  • Red Hat Enterprise Linux Eus: version 8.6 only; version 8.8 only; version 9.0 only; version 9.2 only
  • Red Hat Enterprise Linux For Arm 64: version 8.0_aarch64 only
  • Red Hat Enterprise Linux For IBM Z Systems: version 8.0_s390x only
  • Red Hat Enterprise Linux For Power Little Endian: version 8.0_ppc64le only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 8.2 only; version 8.4 only; version 8.6 only; version 9.2 only
  • Red Hat Enterprise Linux Server Tus: version 8.2 only; version 8.4 only; version 8.6 only; version 8.8 only; version 9.2 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only
  • Squid-Cache Squid: from 3.2.0.1, before 6.4 (fixed in 6.4)

Published 2023-11-03. Last modified 2026-08-07.