Описание
Security update for curl
This update for curl fixes the following issues:
- CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440).
- CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402).
- CVE-2026-8458: wrong reuse for different services (bsc#1268407).
- CVE-2026-8924: traling dot domain super cookie (bsc#1268409).
- CVE-2026-9547: SSH improper host validation (bsc#1268420).
- CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422).
Список пакетов
SUSE Linux Enterprise Server 12 SP5-LTSS
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
Ссылки
- Link for SUSE-SU-2026:3814-1
- E-Mail link for SUSE-SU-2026:3814-1
- SUSE Security Ratings
- SUSE Bug 1263440
- SUSE Bug 1268402
- SUSE Bug 1268407
- SUSE Bug 1268409
- SUSE Bug 1268420
- SUSE Bug 1268422
- SUSE CVE CVE-2026-10536 page
- SUSE CVE CVE-2026-7168 page
- SUSE CVE CVE-2026-8286 page
- SUSE CVE CVE-2026-8458 page
- SUSE CVE CVE-2026-8924 page
- SUSE CVE CVE-2026-9547 page
Описание
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.
Затронутые продукты
Ссылки
- CVE-2026-10536
- SUSE Bug 1268422
Описание
Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Proxy-Authorization:` header field meant for `proxyA`, to `proxyB`.
Затронутые продукты
Ссылки
- CVE-2026-7168
- SUSE Bug 1263440
- SUSE Bug 1268413
- SUSE Bug 1268426
Описание
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.
Затронутые продукты
Ссылки
- CVE-2026-8286
- SUSE Bug 1268402
Описание
libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.
Затронутые продукты
Ссылки
- CVE-2026-8458
- SUSE Bug 1268407
Описание
A flaw in curl's cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.
Затронутые продукты
Ссылки
- CVE-2026-8924
- SUSE Bug 1268409
Описание
When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.
Затронутые продукты
Ссылки
- CVE-2026-9547
- SUSE Bug 1268420