UbuntuUpdates.org

Package "libcurl4-doc"

Name: libcurl4-doc

Description:

documentation for libcurl

Latest version: 7.81.0-1ubuntu1.29
Release: jammy (22.04)
Level: security
Repository: main
Head package: curl
Homepage: https://curl.haxx.se

Links


Download "libcurl4-doc"


Other versions of "libcurl4-doc" in Jammy

Repository Area Version
base main 7.81.0-1
updates main 7.81.0-1ubuntu1.29

Changelog

Version: 7.81.0-1ubuntu1.29 2026-09-24 17:07:27 UTC

curl (7.81.0-1ubuntu1.29) jammy-security; urgency=medium

  [ Charles Cocharn ]
  * SECURITY UPDATE: Use after free in HTTP/2 server push.
    - debian/patches/CVE-2026-18924.patch: make server push transfers
      inherit share from parent in lib/http2.c.
    - CVE-2026-18924
  * SECURITY UPDATE: Public key pinning bypass.
    - debian/patches/CVE-2026-80230.patch: require server cert if public
      key pinned in lib/vtls/openssl.c.
    - CVE-2026-80230
  * SECURITY UPDATE: Cookie injection for public suffix domains.
    - debian/patches/CVE-2026-82209.patch: ensure cookies set for an exact
      PSL domain are host-only in lib/cookie.c, tests/data/Makefile.inc,
      tests/data/test1136, tests/data/test2318.
    - CVE-2026-82209

  [ Kyle Kernick ]
  * SECURITY REGRESSION: checksrc errors and failing test case for
    CVE-2026-8927 (LP #2167779)
    - debian/patches/CVE-2026-6429.patch: Fix indentation to fix
      autopkgtests in lib/transfer.c.
    - debian/patches/CVE-2026-8458.patch: Wrap long lines and fix
      indentation to fix autopkgtests in lib/curl_sasl.c.
    - debian/patches/CVE-2026-8932.patch: Wrap long lines to fix
      autopkgtests in lib/url.c, lib/vtls/nss.c, and lib/vtls/openssl.c.
    - debian/patches/CVE-2026-8927.patch: Fix failing test

 -- Charles Cochran Fri, 18 Sep 2026 11:47:53 -0400

Source diff to previous version
2167779 Reverted security upload 8.20.0-2ubuntu4, broken checksrc and CVE-2026-8927 backport
CVE-2026-18924 A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-af
CVE-2026-80230 When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL
CVE-2026-82209 When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domai
CVE-2026-8927 When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentic
CVE-2026-6429 When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the f
CVE-2026-8458 libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different
CVE-2026-8932 libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. li

Version: 7.81.0-1ubuntu1.27 2026-08-25 18:07:26 UTC
No changelog available yet.
Source diff to previous version

Version: 7.81.0-1ubuntu1.26 2026-08-19 18:07:35 UTC
No changelog available yet.
Source diff to previous version

Version: 7.81.0-1ubuntu1.25 2026-07-01 02:07:43 UTC

  curl (7.81.0-1ubuntu1.25) jammy-security; urgency=medium

  * SECURITY UPDATE: Connection reuse for starttls protocols.
    - debian/patches/CVE-2026-8286.patch: When a connection is tested for
      reuse in a transfer that may upgrade to TLS (commonly via STARTTLS),
      the SSL configuration must match the existing connection in lib/url.c
    - CVE-2026-8286
  * SECURITY UPDATE: Connection reuse in SASL.
    - debian/patches/CVE-2026-8458.patch: Fix erroneous connection reuse in
      in lib/curl_sasl.c, lib/http_negotiate.c, lib/http_ntlm.c, lib/imap.c,
      lib/openldap.c, and lib/pop3.c
    - CVE-2026-8458
  * SECURITY UPDATE: Cookie injection in is_public_suffix.
    - debian/patches/CVE-2026-8924.patch: Trim trailing dots when checking
      PSL in lib/cookie.c.
    - CVE-2026-8924
  * SECURITY UPDATE: Double-free in gsasl.
    - debian/patches/CVE-2026-8925.patch: Require libgasl 1.6.0 to handle
      NULL argument in lib/vauth/gsasl.c.
    - CVE-2026-8925
  * SECURITY UPDATE: Information disclosure in libcurl
    - debian/patches/CVE-2026-8927.patch: Detect if proxy is not the same as
      previous and flush state in lib/url.c and lib/urldata.h.
    - CVE-2026-8927
  * SECURITY UPDATE: Man-in-the-middle in libcurl.
    - debian/patches/CVE-2026-9547.patch: Reject host key mismatches in
      in lib/vssh/libssh.c
    - CVE-2026-9547

 -- Kyle Kernick <email address hidden> Mon, 29 Jun 2026 11:21:28 -0600

Source diff to previous version

Version: 7.81.0-1ubuntu1.24 2026-05-04 15:34:37 UTC

  curl (7.81.0-1ubuntu1.24) jammy-security; urgency=medium

  * SECURITY UPDATE: connection reuse ignores TLS requirement
    - debian/patches/CVE-2026-4873.patch: do not reuse a non-tls starttls
      connection if new requires TLS in lib/url.c.
    - CVE-2026-4873
  * SECURITY UPDATE: wrong reuse of HTTP Negotiate connection
    - debian/patches/CVE-2026-5545.patch: improve connection reuse on
      negotiate in lib/url.c.
    - CVE-2026-5545
  * SECURITY UPDATE: wrong reuse of SMB connection
    - debian/patches/CVE-2026-5773.patch: disable connection reuse for
      SMB(S) in lib/smb.c.
    - CVE-2026-5773
  * SECURITY UPDATE: proxy credentials leak over redirect-to proxy
    - debian/patches/CVE-2026-6253.patch: clear the proxy credentials as
      well on port or scheme change in lib/transfer.*, tests/*.
    - CVE-2026-6253
  * SECURITY UPDATE: stale custom cookie host causes cookie leak
    - debian/patches/CVE-2026-6276.patch: move cookiehost to struct
      SingleRequest in lib/http.c, lib/url.c, lib/urldata.h, tests/*.
    - CVE-2026-6276
  * SECURITY UPDATE: netrc credential leak with reused proxy connection
    - debian/patches/CVE-2026-6429-pre1.patch: prevent secure schemes
      pushed over insecure connections in lib/http2.c.
    - debian/patches/CVE-2026-6429-pre2.patch: same origin tests in
      lib/http2.c, lib/urlapi-int.h, lib/urlapi.c.
    - debian/patches/CVE-2026-6429.patch: clear credentials better on
      redirect in lib/transfer.c, tests/*.
    - CVE-2026-6429
  * SECURITY UPDATE: cross-proxy Digest auth state leak
    - debian/patches/CVE-2026-7168.patch: clear proxy auth properties when
      switching in lib/setopt.c, lib/vauth/vauth.h, tests/*.
    - CVE-2026-7168
  * debian/rules: run test suite with extra debugging information.

 -- Marc Deslauriers <email address hidden> Wed, 29 Apr 2026 07:35:43 -0400




About   -   Send Feedback to @ubuntu_updates