Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-3805

Опубликовано: 11 мар. 2026
Источник: redhat
CVSS3: 6.3

Описание

When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.

A flaw was found in curl. When handling a second Server Message Block (SMB) request to the same host, curl incorrectly accesses memory that has already been freed. This memory corruption vulnerability, known as a use-after-free, could allow a remote attacker to potentially execute arbitrary code or cause a denial of service.

Отчет

This Moderate flaw in curl's handling of Server Message Block (SMB) connections can lead to a use-after-free vulnerability. When a second SMB request is made to the same host, curl may incorrectly access previously freed memory, potentially resulting in arbitrary code execution or a denial of service. However, successful exploitation is considered difficult due to the specific conditions required to trigger the flaw reliably.

Меры по смягчению последствий

To mitigate this issue, avoid using curl for Server Message Block (SMB) transfers. This can be achieved by ensuring that applications utilizing curl do not initiate SMB requests. If SMB transfers are essential, consider isolating the affected systems or restricting network access to SMB services. A service restart or reload may be required for changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9Fix deferred
Confidential Compute Attestationconfidential-compute-attestation-tech-preview/trustee-rhel9Fix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-operator-bundleFix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-builder-rhel9Fix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Fix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-rhel9-operatorFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-operator-bundleFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-rhel9-operatorFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/eventrouter-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/fluentd-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2446451curl: curl: Arbitrary code execution or Denial of Service via use-after-free in SMB request handling

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.

CVSS3: 7.5
nvd
5 месяцев назад

When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.

msrc
4 месяца назад

use after free in SMB connection reuse

CVSS3: 7.5
debian
5 месяцев назад

When doing a second SMB request to the same host again, curl would wro ...

CVSS3: 7.5
github
5 месяцев назад

When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.

6.3 Medium

CVSS3