CVE-2025-59362 Overview
CVE-2025-59362 affects Squid caching proxy versions through 7.1. The vulnerability resides in the asn_build_objid function in lib/snmplib/asn1.c. Squid mishandles ASN.1 (Abstract Syntax Notation One) encoding of long Simple Network Management Protocol (SNMP) Object Identifiers (OIDs). The flaw is classified as a stack-based buffer overflow [CWE-121]. The attack vector is local, with impact limited to availability. No known exploitation in the wild has been reported, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog.
Critical Impact
Local processing of malformed long SNMP OIDs can trigger a stack-based buffer overflow in the Squid SNMP library, leading to a denial of service condition.
Affected Products
- Squid-cache Squid through version 7.1
- Deployments with SNMP support compiled and enabled
- Systems using the bundled snmplib ASN.1 encoder
Discovery Timeline
- 2025-09-26 - CVE-2025-59362 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-59362
Vulnerability Analysis
Squid is a widely deployed caching and forwarding HTTP proxy. It includes an embedded SNMP library (snmplib) used to expose runtime metrics. The vulnerable routine asn_build_objid encodes an SNMP Object Identifier into ASN.1 Basic Encoding Rules (BER) format. When the OID exceeds the size assumptions built into the function, the encoding process writes past the bounds of a stack buffer.
The issue is scoped to local availability impact. An attacker capable of supplying an oversized OID to the SNMP encoding path can crash the Squid process. This produces a denial of service against the proxy service. The Exploit Prediction Scoring System (EPSS) probability is low, and no public proof-of-concept exploit is available.
Root Cause
The root cause is insufficient bounds checking during ASN.1 length and content encoding of long OIDs in asn_build_objid. The routine assumes OID components fit within a fixed stack buffer. Supplying an OID with many sub-identifiers, or sub-identifiers requiring multi-byte base-128 encoding, exceeds that buffer. This corresponds to the [CWE-121] stack-based buffer overflow class.
Attack Vector
Exploitation requires a local attack path against the SNMP encoding code path in Squid. The vulnerability requires no privileges and no user interaction, but the local attack vector constrains remote reachability. Successful triggering results in memory corruption on the stack and process termination, disrupting proxy availability. Confidentiality and integrity are not directly impacted according to the published CVSS metrics.
No verified public exploit code is available. See the GitHub Security Advisory CVE-2025-59362 for the technical write-up and the upstream fix in Squid Pull Request #2149 for remediation details.
Detection Methods for CVE-2025-59362
Indicators of Compromise
- Unexpected termination or crash of the squid process with stack corruption signatures in core dumps
- Segmentation faults logged against SNMP request handling in cache.log
- Repeated restarts of the Squid service coinciding with SNMP traffic to the proxy
Detection Strategies
- Inventory Squid deployments and flag any instance running version 7.1 or earlier with SNMP enabled
- Inspect SNMP request payloads reaching the proxy for abnormally long OIDs with many sub-identifiers
- Correlate Squid crash events with preceding SNMP activity in host telemetry
Monitoring Recommendations
- Forward Squid cache.log and system journal entries into a centralized log platform for crash pattern analysis
- Monitor process uptime and restart counts for the squid binary as an availability signal
- Alert on core dump generation by the Squid process
How to Mitigate CVE-2025-59362
Immediate Actions Required
- Upgrade Squid to a version that incorporates the fix from Squid Pull Request #2149
- Disable the SNMP module in Squid configuration if runtime metrics via SNMP are not required
- Restrict access to the SNMP listening port using host and network firewall rules
Patch Information
The upstream fix is tracked in Squid Pull Request #2149, which corrects the ASN.1 encoding of long OIDs in asn_build_objid within lib/snmplib/asn1.c. Rebuild Squid from a patched source tree or install a distribution package that backports the change. Verify the running version after upgrade and restart the service to load the fixed binary.
Workarounds
- Compile Squid without SNMP support using --disable-snmp at build time when metrics are collected by other means
- Bind the SNMP listener to the loopback interface only, if SNMP is required for local monitoring
- Apply access control lists in squid.conf to reject SNMP queries from untrusted sources
# Configuration example: disable SNMP in squid.conf
# Comment out or remove SNMP directives
# snmp_port 3401
# acl snmppublic snmp_community public
# snmp_access allow snmppublic localhost
# snmp_access deny all
# Verify Squid version after patching
squid -v | head -n 1
# Restart the service to apply changes
systemctl restart squid
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.