Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-8925

Опубликовано: 03 июл. 2026
Источник: debian
EPSS Низкий

Описание

The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
curlfixed8.21.0~rc2-1package
curlnot-affectedtrixiepackage
curlnot-affectedbookwormpackage
curlnot-affectedbullseyepackage

Примечания

  • https://curl.se/docs/CVE-2026-8925.html

  • Introduced with: https://github.com/curl/curl/commit/ab650379a8c25ca952f651476d25b4cdd77bb3fc (curl-8_15_0)

  • Fixed by: https://github.com/curl/curl/commit/3da249e1f0716c06644ed3522a37a8bf81808012 (rc-8_21_0-1, curl-8_21_0)

EPSS

Процентиль: 45%
0.00592
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
28 дней назад

The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.

CVSS3: 8.1
redhat
28 дней назад

The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.

CVSS3: 9.8
nvd
28 дней назад

The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.

msrc
25 дней назад

SASL double-free

CVSS3: 9.8
github
28 дней назад

The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.

EPSS

Процентиль: 45%
0.00592
Низкий