Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-3805

Опубликовано: 11 мар. 2026
Источник: debian
EPSS Низкий

Описание

When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
curlfixed8.19.0-1package
curlfixed8.14.1-2+deb13u4trixiepackage
curlnot-affectedbookwormpackage
curlnot-affectedbullseyepackage

Примечания

  • https://curl.se/docs/CVE-2026-3805.html

  • Introduced with: https://github.com/curl/curl/commit/f4831daa9b2a97e8a2921d6b62cc4dfdd0d8646e (curl-8_13_0)

  • Fixed by: https://github.com/curl/curl/commit/e090be9f73a7a71459ef678c7cc4b1f75e3ea883 (curl-8_19_0)

EPSS

Процентиль: 51%
0.00745
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.

CVSS3: 6.3
redhat
5 месяцев назад

When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.

CVSS3: 7.5
nvd
5 месяцев назад

When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.

msrc
4 месяца назад

use after free in SMB connection reuse

CVSS3: 7.5
github
5 месяцев назад

When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.

EPSS

Процентиль: 51%
0.00745
Низкий