Описание
Security update for curl
This update for curl fixes the following issues
- CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402).
- CVE-2026-8458: wrong reuse for different services (bsc#1268407).
- CVE-2026-8924: traling dot domain super cookie (bsc#1268409).
- CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413).
- CVE-2026-9079: stale proxy password leak (bsc#1268415).
- CVE-2026-9080: UAF after pause in socket callback (bsc#1268416).
- CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417).
- CVE-2026-9547: SSH improper host validation (bsc#1268420).
- CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422).
- CVE-2026-12064: proto-default skips SSH verification (bsc#1268427).
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1268402
- SUSE Bug 1268407
- SUSE Bug 1268409
- SUSE Bug 1268413
- SUSE Bug 1268415
- SUSE Bug 1268416
- SUSE Bug 1268417
- SUSE Bug 1268420
- SUSE Bug 1268422
- SUSE Bug 1268427
- SUSE CVE CVE-2026-10536 page
- SUSE CVE CVE-2026-12064 page
- SUSE CVE CVE-2026-8286 page
- SUSE CVE CVE-2026-8458 page
- SUSE CVE CVE-2026-8924 page
- SUSE CVE CVE-2026-8927 page
- SUSE CVE CVE-2026-9079 page
- SUSE CVE CVE-2026-9080 page
- SUSE CVE CVE-2026-9545 page
Описание
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.
Затронутые продукты
Ссылки
- CVE-2026-10536
- SUSE Bug 1268422
Описание
When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error.
Затронутые продукты
Ссылки
- CVE-2026-12064
- SUSE Bug 1268427
Описание
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.
Затронутые продукты
Ссылки
- CVE-2026-8286
- SUSE Bug 1268402
Описание
libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.
Затронутые продукты
Ссылки
- CVE-2026-8458
- SUSE Bug 1268407
Описание
A flaw in curl's cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.
Затронутые продукты
Ссылки
- CVE-2026-8924
- SUSE Bug 1268409
Описание
When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.
Затронутые продукты
Ссылки
- CVE-2026-8927
- SUSE Bug 1263440
- SUSE Bug 1268413
Описание
libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.
Затронутые продукты
Ссылки
- CVE-2026-9079
- SUSE Bug 1268415
Описание
Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed.
Затронутые продукты
Ссылки
- CVE-2026-9080
- SUSE Bug 1268416
Описание
In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate. When libcurl returns to the hostname the second time with a cached SSL session (`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the `CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might send off the second request's bytes on that new connection *before* enforcing the certificate verification failure. Potentially leaking sensitive information.
Затронутые продукты
Ссылки
- CVE-2026-9545
- SUSE Bug 1268417
Описание
When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.
Затронутые продукты
Ссылки
- CVE-2026-9547
- SUSE Bug 1268420