Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-9080

Опубликовано: 03 июл. 2026
Источник: ubuntu
Приоритет: low
CVSS3: 7.3

Описание

Calling curl_easy_pause() within the event-based CURLMOPT_SOCKETFUNCTION callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed.

РелизСтатусПримечание
devel

needed

esm-infra-legacy/trusty

not-affected

code not present
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
questing

released

8.14.1-2ubuntu1.4
resolute

released

8.18.0-1ubuntu2.2
upstream

pending

8.21.0

Показывать по

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
redhat
28 дней назад

Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed.

CVSS3: 7.3
nvd
28 дней назад

Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed.

msrc
27 дней назад

UAF after pause in socket callback

CVSS3: 7.3
debian
28 дней назад

Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUN ...

CVSS3: 7.3
github
28 дней назад

Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed.

7.3 High

CVSS3