Package "curl"
| Name: |
curl
|
Description: |
command line tool for transferring data with URL syntax
|
| Latest version: |
8.18.0-1ubuntu2.7 |
| Release: |
resolute (26.04) |
| Level: |
updates |
| Repository: |
main |
| Homepage: |
https://curl.se/ |
Links
Download "curl"
Other versions of "curl" in Resolute
Packages in group
Deleted packages are displayed in grey.
Changelog
|
curl (8.18.0-1ubuntu2.7) resolute-security; urgency=medium
[ Charles Cochran ]
* SECURITY UPDATE: Authentication bypass in LDAP SASL negotiation.
- debian/patches/CVE-2026-13608.patch: openldap: handle
Curl_sasl_continue() returns better in lib/openldap.c.
- CVE-2026-13608
* SECURITY UPDATE: Use after free in HTTP/2 server push.
- debian/patches/CVE-2026-18924.patch: make server push transfers
inherit share from parent in lib/http2.c.
- CVE-2026-18924
* SECURITY UPDATE: Use after free in OpenSSL library context.
- debian/patches/CVE-2026-80229.patch: avoid conn reuse if provider is
used in lib/vtls/openssl.c.
- CVE-2026-80229
* SECURITY UPDATE: Public key pinning bypass.
- debian/patches/CVE-2026-80230.patch: require server cert if public
key pinned in lib/vtls/openssl.c.
- CVE-2026-80230
* SECURITY UPDATE: Cookie Secure attribute bypass in Set-Cookie.
- debian/patches/CVE-2026-80255.patch: improve TAB handling in
lib/cookie.c, tests/data/Makefile.am, tests/data/test2885.
- CVE-2026-80255
* SECURITY UPDATE: Cookie injection for public suffix domains.
- debian/patches/CVE-2026-82209.patch: ensure cookies set for an exact
PSL domain are host-only in lib/cookie.c, tests/data/Makefile.am,
tests/data/test1136, tests/data/test2318, tests/data/test798.
- CVE-2026-82209
* SECURITY REGRESSION: CVE-2026-9080: upstream pt 2 needed (LP: #2167969)
- debian/patches/CVE-2026-9080-post1.patch: multi_ev: refresh sock
entry after remove callback in lib/multi_ev.c.
[ Kyle Kernick ]
* SECURITY REGRESSION: checksrc errors and failing test case for
CVE-2026-8927 (LP #2167779)
- debian/patches/CVE-2026-11856.patch: Use curlx_strdup to fix
autopkgtests
- debian/patches/CVE-2026-8458.patch: Wrap long lines and remove unused
variable to fix autopkgtests
- debian/patches/CVE-2026-8927.patch: Fix failing test
-- Charles Cochran Fri, 18 Sep 2026 14:17:09 -0400
|
| Source diff to previous version |
| 2167969 |
Upstream update to CVE-2026-9080 fix missing in Resolute |
| 2167779 |
Reverted security upload 8.20.0-2ubuntu4, broken checksrc and CVE-2026-8927 backport |
| CVE-2026-13608 |
A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptogra |
| CVE-2026-18924 |
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-af |
| CVE-2026-80229 |
When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider con |
| CVE-2026-80230 |
When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL |
| CVE-2026-80255 |
A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes cur |
| CVE-2026-82209 |
When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domai |
| CVE-2026-9080 |
Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts |
| CVE-2026-8927 |
When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentic |
| CVE-2026-11856 |
Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a diff |
| CVE-2026-8458 |
libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different |
|
|
curl (8.18.0-1ubuntu2.5) resolute-security; urgency=medium
* SECURITY UPDATE: Authentication Bypass in connection reuse.
- debian/patches/CVE-2026-8932.patch: Fix incomplete mTLS config in
lib/ldap.c, ../urldata.h, lib/vssh/libssh.c, ../libssh2.c,
lib/vtls/gtls.c, ../mbedtls.c, ../openssl.c, ../rustls.c,
../schannel.c, ../vtls.c, ../vtls_scache.c, ../vtls_scache.h,
and ../wolfssl.c.
- CVE-2026-8932
-- Kyle Kernick Fri, 21 Aug 2026 12:55:56 -0600
|
| Source diff to previous version |
| CVE-2026-8932 |
libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. li |
|
|
curl (8.18.0-1ubuntu2.3) resolute-security; urgency=medium
* SECURITY UPDATE: Use after free in curl_easy_reset.
- debian/patches/CVE-2026-10536.patch: Deprecate CURLOPT_* in
include/curl/curl.h, lib/http2.c,
lib/setopt.c, lib/url.c, and lib/urldata.h
- CVE-2026-10536
* SECURITY UPDATE: Denial of service in QUIC UDP.
- debian/patches/CVE-2026-11352.patch: Count zero-length UDP packets
and enforce an upper bound in
lib/vquic/vquic.c
- CVE-2026-11352
* SECURITY UPDATE: Improper certificate validation in native_ca_store.
- debian/patches/CVE-2026-11564.patch: Add bit native_ca_store_opt to
keep the setting of CURLOPT_(PROXY_)SSL_OPTIONS and use that to
calculate every easy transfer if a native CA store shall be used or
not in lib/doh.c, lib/setopt.c, and lib/vtls/vtls.c
- CVE-2026-11564
* SECURITY UPDATE: Memory exhaustion in ws.c
- debian/patches/CVE-2026-11586.patch: Do not send PONG frames unless
there is sufficient space left in the websocket send buffer in
lib/ws.c.
- CVE-2026-11586
* SECURITY UPDATE: Improper validation in config2setopts.
- debian/patches/CVE-2026-12064.patch: Use default protocol properly in
src/config2setopts.c.
- CVE-2026-12064
-- Kyle Kernick <email address hidden> Mon, 06 Jul 2026 10:45:44 -0600
|
| Source diff to previous version |
| CVE-2026-10536 |
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CUR |
| CVE-2026-11352 |
An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. |
| CVE-2026-11564 |
libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle th |
| CVE-2026-11586 |
By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a |
| CVE-2026-12064 |
When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl |
|
|
curl (8.18.0-1ubuntu2.2) resolute-security; urgency=medium
* SECURITY UPDATE: Connection reuse for starttls protocols.
- debian/patches/CVE-2026-8286.patch: When a connection is tested for
reuse in a transfer that may upgrade to TLS (commonly via STARTTLS),
the SSL configuration must match the existing connection in lib/url.c
- CVE-2026-8286
* SECURITY UPDATE: Connection reuse in SASL.
- debian/patches/CVE-2026-8458.patch: Fix erroneous connection reuse in
in lib/curl_sasl.c, lib/http_negotiate.c, lib/http_ntlm.c, lib/imap.c,
lib/openldap.c, and lib/pop3.c
- CVE-2026-8458
* SECURITY UPDATE: Cookie injection in is_public_suffix.
- debian/patches/CVE-2026-8924.patch: Trim trailing dots when checking
PSL in lib/cookie.c.
- CVE-2026-8924
* SECURITY UPDATE: Double-free in gsasl.
- debian/patches/CVE-2026-8925.patch: Require libgasl 1.6.0 to handle
NULL argument in lib/vauth/gsasl.c.
- CVE-2026-8925
* SECURITY UPDATE: Information disclosure in netrc.
- debian/patches/CVE-2026-8926.patch: Do not return a password from
parsenetrc() when the requested login did not match the credentials
found for the matched machine in lib/netrc.c.
- CVE-2026-8926
* SECURITY UPDATE: Information disclosure in libcurl
- debian/patches/CVE-2026-8927.patch: Detect if proxy is not the same as
previous and flush state in lib/url.c and lib/urldata.h.
- debian/patches/CVE-2026-9079.patch: Verify NULLed proxy credentials
in lib/setopt.c.
- debian/patches/CVE-2026-9545.patch: Hard fail when certificate
verification fails in lib/vquic/curl_ngtcp2.c.
- CVE-2026-8927
- CVE-2026-9079
- CVE-2026-9545
* SECURITY UPDATE: Use-after-free in curl_easy_parse
- debian/patches/CVE-2026-9080.patch: Introduce magic struct field to
assert against NULL pointers in lib/multi_ev.c
- CVE-2026-9080
* SECURITY UPDATE: Man-in-the-middle in libcurl.
- debian/patches/CVE-2026-9547.patch: Reject host key mismatches in
in lib/vssh/libssh.c
- CVE-2026-9547
-- Kyle Kernick <email address hidden> Thu, 25 Jun 2026 15:11:42 -0600
|
About
-
Send Feedback to @ubuntu_updates