|
|
Log in / Subscribe / Register

Ubuntu alert USN-8487-1 (curl)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8487-1] curl vulnerabilities
Date:  Wed, 01 Jul 2026 02:09:32 +0000
Message-ID:  <E1wekOK-0007nn-Ba@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8487-1 June 30, 2026 curl vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in curl. Software Description: - curl: HTTP, HTTPS, and FTP client and client libraries Details: Andrew Nesbitt discovered that curl could reuse an existing live connection during STARTTLS-based connection upgrades even when the TLS configuration did not match. A remote attacker could possibly use this issue to cause curl to use an unintended TLS configuration. (CVE-2026-8286) Muhamad Arga Reksapati discovered that curl incorrectly reused connections for Negotiate-authenticated requests when different services were involved. A remote attacker could possibly use this issue to access resources authenticated for another service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-8458) It was discovered that curl incorrectly handled cookie parsing in certain circumstances. A remote attacker could possibly use this issue to set cookies that would be transmitted to unrelated third-party domains. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-8924) Joshua Rogers discovered that curl could double-free a GSASL context when handling SASL authentication. A remote attacker could possibly use this issue to cause a denial of service, or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-8925) Joshua Rogers discovered that curl could select the wrong password from a .netrc file when a username was specified in the URL without a password. A remote attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-8926) Ady Elouej discovered that curl did not clear proxy authentication state between requests when reusing a handle with environment-variable proxy configuration. A remote attacker could possibly use this issue to obtain sensitive credentials. (CVE-2026-8927) Guannan Wang, Zhanpeng Liu, Jiashuo Liang, and Guancheng Li discovered that curl did not properly clear proxy authentication credentials when instructed to do so. A remote attacker could possibly use this issue to obtain sensitive credentials. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-9079) Joshua Rogers discovered that curl contained a use-after-free when curl_easy_pause() was called within the event-based socket callback. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-9080) Eunsoo Kim discovered that curl could send early data on a resumed TLS session before enforcing certificate verification failure. A machine-in-the-middle attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-9545) Joshua Rogers discovered that curl did not properly reject host key type mismatches when using the SSH key callback for SCP and SFTP transfers. A machine-in-the-middle attacker could possibly use this issue to impersonate a trusted server. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-9547) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS curl 8.18.0-1ubuntu2.2 libcurl3t64-gnutls 8.18.0-1ubuntu2.2 libcurl4-gnutls-dev 8.18.0-1ubuntu2.2 libcurl4-openssl-dev 8.18.0-1ubuntu2.2 libcurl4t64 8.18.0-1ubuntu2.2 Ubuntu 25.10 curl 8.14.1-2ubuntu1.4 libcurl3t64-gnutls 8.14.1-2ubuntu1.4 libcurl4-gnutls-dev 8.14.1-2ubuntu1.4 libcurl4-openssl-dev 8.14.1-2ubuntu1.4 libcurl4t64 8.14.1-2ubuntu1.4 Ubuntu 24.04 LTS curl 8.5.0-2ubuntu10.10 libcurl3t64-gnutls 8.5.0-2ubuntu10.10 libcurl4-gnutls-dev 8.5.0-2ubuntu10.10 libcurl4-openssl-dev 8.5.0-2ubuntu10.10 libcurl4t64 8.5.0-2ubuntu10.10 Ubuntu 22.04 LTS curl 7.81.0-1ubuntu1.25 libcurl3-gnutls 7.81.0-1ubuntu1.25 libcurl3-nss 7.81.0-1ubuntu1.25 libcurl4 7.81.0-1ubuntu1.25 libcurl4-gnutls-dev 7.81.0-1ubuntu1.25 libcurl4-nss-dev 7.81.0-1ubuntu1.25 libcurl4-openssl-dev 7.81.0-1ubuntu1.25 Ubuntu 20.04 LTS curl 7.68.0-1ubuntu2.25+esm4 Available with Ubuntu Pro libcurl3-gnutls 7.68.0-1ubuntu2.25+esm4 Available with Ubuntu Pro libcurl3-nss 7.68.0-1ubuntu2.25+esm4 Available with Ubuntu Pro libcurl4 7.68.0-1ubuntu2.25+esm4 Available with Ubuntu Pro libcurl4-gnutls-dev 7.68.0-1ubuntu2.25+esm4 Available with Ubuntu Pro libcurl4-nss-dev 7.68.0-1ubuntu2.25+esm4 Available with Ubuntu Pro libcurl4-openssl-dev 7.68.0-1ubuntu2.25+esm4 Available with Ubuntu Pro Ubuntu 18.04 LTS curl 7.58.0-2ubuntu3.24+esm9 Available with Ubuntu Pro libcurl3-gnutls 7.58.0-2ubuntu3.24+esm9 Available with Ubuntu Pro libcurl3-nss 7.58.0-2ubuntu3.24+esm9 Available with Ubuntu Pro libcurl4 7.58.0-2ubuntu3.24+esm9 Available with Ubuntu Pro libcurl4-gnutls-dev 7.58.0-2ubuntu3.24+esm9 Available with Ubuntu Pro libcurl4-nss-dev 7.58.0-2ubuntu3.24+esm9 Available with Ubuntu Pro libcurl4-openssl-dev 7.58.0-2ubuntu3.24+esm9 Available with Ubuntu Pro Ubuntu 16.04 LTS curl 7.47.0-1ubuntu2.19+esm16 Available with Ubuntu Pro libcurl3 7.47.0-1ubuntu2.19+esm16 Available with Ubuntu Pro libcurl3-gnutls 7.47.0-1ubuntu2.19+esm16 Available with Ubuntu Pro libcurl3-nss 7.47.0-1ubuntu2.19+esm16 Available with Ubuntu Pro libcurl4-gnutls-dev 7.47.0-1ubuntu2.19+esm16 Available with Ubuntu Pro libcurl4-nss-dev 7.47.0-1ubuntu2.19+esm16 Available with Ubuntu Pro libcurl4-openssl-dev 7.47.0-1ubuntu2.19+esm16 Available with Ubuntu Pro Ubuntu 14.04 LTS curl 7.35.0-1ubuntu2.20+esm20 Available with Ubuntu Pro libcurl3 7.35.0-1ubuntu2.20+esm20 Available with Ubuntu Pro libcurl3-gnutls 7.35.0-1ubuntu2.20+esm20 Available with Ubuntu Pro libcurl3-nss 7.35.0-1ubuntu2.20+esm20 Available with Ubuntu Pro libcurl4-gnutls-dev 7.35.0-1ubuntu2.20+esm20 Available with Ubuntu Pro libcurl4-nss-dev 7.35.0-1ubuntu2.20+esm20 Available with Ubuntu Pro libcurl4-openssl-dev 7.35.0-1ubuntu2.20+esm20 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8487-1 CVE-2026-8286, CVE-2026-8458, CVE-2026-8924, CVE-2026-8925, CVE-2026-8926, CVE-2026-8927, CVE-2026-9079, CVE-2026-9080, CVE-2026-9545, CVE-2026-9547 Package Information: https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.2 https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.4 https://launchpad.net/ubuntu/+source/curl/8.5.0-2ubuntu10.10 https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.25


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmpEdnIACgkQcpJm3tlz hgGwuQ//bp0FPnzLVEnzgRbjKPvhox71bFzZiTVObcHuih84Ekcx5jmBieziR3sD I+0VusXlLwukEb0iSl4ZGZDlYXUcuT5VwF+Pzu/hD/tE9bGUR3UrXaG3NxmpUkUZ 1l8E/vSuzaawPOzKpdf1MCCMvk6igKV00uTMQOV4Rxvltg+Fp0nmK0/owsj+GZ0Y Q1otq4HkP+RlifJlzByJfmONjhrR/F5FHlC8RJfewzRoRhVj67Bp5LhQcRRg+5dN DRJRX7ehl9Frarjwpbrvi5Zl8PvJA6v8FD5zxRZfm3UvGjU8sRkDRRQ7HJJ91Czg UngCZyT+WfqIA9EJtoM9B2iRqEPSG9g28zInHUwUf7dtAr4v6NQXew9G9sOOG1Pu gOMFA0PkHtyW+N70OtYDz9/tUXF/tTlV5fG6J4aIT1M3oUR0aagJr66UmBGkqp7y NUbSK/ne2xU0ThtuqLDJ8stlk2IoeQU02FXQVDCwctxOLfwttRypyurgcoI06U/Y k7b4X29umxslcJsG1H1CUfEUQOFP1IYts4yyX0Ty7m+HUkj/wEHUJQA6jIs89wPF NCDRge2pblKE5F3D3V4XWdYPKJTFuQLnU4z5iMVzIr2Wwxq0JIjTEwLOKVuFWWyi K98JKtBWR3HKWD57ekz6BZkXMKFqLdY8iT1taPsDJAb6RAmCki0= =x6tL -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds