Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:4048-1

Опубликовано: 07 сент. 2026
Источник: suse-cvrf

Описание

Security update for curl

This update for curl fixes the following issues:

  • CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476).
  • CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479).
  • CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480).

Список пакетов

Container bci/bci-sle15-kernel-module-devel:latest
libcurl4-8.14.1-150700.7.26.1
Container bci/golang:1.25
curl-8.14.1-150700.7.26.1
libcurl4-8.14.1-150700.7.26.1
Container bci/golang:1.25-openssl
curl-8.14.1-150700.7.26.1
libcurl4-8.14.1-150700.7.26.1
Container bci/golang:1.26
curl-8.14.1-150700.7.26.1
libcurl4-8.14.1-150700.7.26.1
Container bci/golang:latest
curl-8.14.1-150700.7.26.1
libcurl4-8.14.1-150700.7.26.1
Container bci/node:22
curl-8.14.1-150700.7.26.1
libcurl4-8.14.1-150700.7.26.1
Container bci/openjdk:17
curl-8.14.1-150700.7.26.1
libcurl4-8.14.1-150700.7.26.1
Container bci/openjdk:21
curl-8.14.1-150700.7.26.1
libcurl4-8.14.1-150700.7.26.1
Container bci/openjdk:latest
curl-8.14.1-150700.7.26.1
libcurl4-8.14.1-150700.7.26.1
Container bci/python:3
curl-8.14.1-150700.7.26.1
libcurl4-8.14.1-150700.7.26.1
Container bci/python:latest
curl-8.14.1-150700.7.26.1
libcurl4-8.14.1-150700.7.26.1
Container bci/ruby:2
curl-8.14.1-150700.7.26.1
libcurl4-8.14.1-150700.7.26.1
Container bci/ruby:latest
curl-8.14.1-150700.7.26.1
libcurl4-8.14.1-150700.7.26.1
Container bci/rust:1.97
libcurl4-8.14.1-150700.7.26.1
Container bci/rust:latest
libcurl4-8.14.1-150700.7.26.1
Container bci/spack:latest
curl-8.14.1-150700.7.26.1
libcurl-devel-8.14.1-150700.7.26.1
libcurl4-8.14.1-150700.7.26.1
Container private-registry/1.2/harbor-trivy-adapter:latest
libcurl4-8.14.1-150700.7.26.1
Container private-registry/harbor-trivy-adapter:latest
libcurl4-8.14.1-150700.7.26.1
Container suse/hpc/warewulf4-x86_64/sle-hpc-node:latest
curl-8.14.1-150700.7.26.1
libcurl4-8.14.1-150700.7.26.1
Container suse/kea:2.6
libcurl4-8.14.1-150700.7.26.1
Container suse/kiosk/firefox-esr:latest
libcurl4-8.14.1-150700.7.26.1
Container suse/postgres:16
libcurl4-8.14.1-150700.7.26.1
Container suse/postgres:16.15
libcurl4-8.14.1-150700.7.26.1
Container suse/postgres:17
libcurl4-8.14.1-150700.7.26.1
Container suse/postgres:17.11
libcurl4-8.14.1-150700.7.26.1
Container suse/postgres:latest
libcurl4-8.14.1-150700.7.26.1
Container suse/rmt-server:latest
libcurl4-8.14.1-150700.7.26.1
Container suse/sle15:latest
curl-8.14.1-150700.7.26.1
libcurl4-8.14.1-150700.7.26.1
Image SLES15-SP7-SAPCAL-Azure
curl-8.14.1-150700.7.26.1
libcurl-devel-8.14.1-150700.7.26.1
libcurl4-8.14.1-150700.7.26.1
libcurl4-32bit-8.14.1-150700.7.26.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
curl-8.14.1-150700.7.26.1
libcurl-devel-8.14.1-150700.7.26.1
libcurl4-8.14.1-150700.7.26.1
libcurl4-32bit-8.14.1-150700.7.26.1

Описание

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:libcurl4-8.14.1-150700.7.26.1
Container bci/golang:1.25-openssl:curl-8.14.1-150700.7.26.1
Container bci/golang:1.25-openssl:libcurl4-8.14.1-150700.7.26.1
Container bci/golang:1.25:curl-8.14.1-150700.7.26.1

Ссылки

Описание

When performing transfers via libcurl's multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy handle's state and passes it to OpenSSL without acquiring an ownership reference; destroying the easy handle prematurely frees this context while the active connection retains a dangling pointer, leading to a heap-use-after-free upon subsequent I/O or post-handshake operations.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:libcurl4-8.14.1-150700.7.26.1
Container bci/golang:1.25-openssl:curl-8.14.1-150700.7.26.1
Container bci/golang:1.25-openssl:libcurl4-8.14.1-150700.7.26.1
Container bci/golang:1.25:curl-8.14.1-150700.7.26.1

Ссылки

Описание

When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:libcurl4-8.14.1-150700.7.26.1
Container bci/golang:1.25-openssl:curl-8.14.1-150700.7.26.1
Container bci/golang:1.25-openssl:libcurl4-8.14.1-150700.7.26.1
Container bci/golang:1.25:curl-8.14.1-150700.7.26.1

Ссылки