Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-3805

Опубликовано: 11 мар. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.

РелизСтатусПримечание
devel

released

8.18.0-1ubuntu2
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
questing

released

8.14.1-2ubuntu1.2
upstream

released

8.19.0

Показывать по

EPSS

Процентиль: 12%
0.00039
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 6.3
redhat
15 дней назад

A flaw was found in curl. When handling a second Server Message Block (SMB) request to the same host, curl incorrectly accesses memory that has already been freed. This memory corruption vulnerability, known as a use-after-free, could allow a remote attacker to potentially execute arbitrary code or cause a denial of service.

CVSS3: 7.5
nvd
15 дней назад

When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.

msrc
13 дней назад

use after free in SMB connection reuse

CVSS3: 7.5
debian
15 дней назад

When doing a second SMB request to the same host again, curl would wro ...

CVSS3: 7.5
github
15 дней назад

When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.

EPSS

Процентиль: 12%
0.00039
Низкий

7.5 High

CVSS3