Описание
The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| curl | fixed | 8.21.0~rc2-1 | package | |
| curl | not-affected | trixie | package | |
| curl | not-affected | bookworm | package | |
| curl | not-affected | bullseye | package |
Примечания
https://curl.se/docs/CVE-2026-8925.html
Introduced with: https://github.com/curl/curl/commit/ab650379a8c25ca952f651476d25b4cdd77bb3fc (curl-8_15_0)
Fixed by: https://github.com/curl/curl/commit/3da249e1f0716c06644ed3522a37a8bf81808012 (rc-8_21_0-1, curl-8_21_0)
EPSS
Связанные уязвимости
The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.
The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.
The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.
The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.
EPSS