SB2026021403 - SUSE update for curl
Published: February 14, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 5 secuirty vulnerabilities.
1) Unsynchronized access to shared data in a multithreaded context (CVE-ID: CVE-2025-14017)
The vulnerability allows an attacker to bypass implemented security restrictions.
The vulnerability exists due to an error when performing multithreaded LDAPS transfers (LDAP over TLS) with libcurl. Changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers. For example, disabling certificate verification for a specific transfer could unintentionally disable the feature for other threads as well, leading to a MitM attacks against other websites.
2) Insufficiently protected credentials (CVE-ID: CVE-2025-14524)
The vulnerability allows an attacker to obtain bearer token,
The vulnerability exists due to an error when handling cross-protocol redirects. When an oauth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.
3) Improper Certificate Validation (CVE-ID: CVE-2025-14819)
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to the way libcurl handles TLS transfers when using the CURLSSLOPT_NO_PARTIALCHAIN option. A remote attacker can trick the library into re-using a CA store cached in memory for which the partial chain option was reversed, leading to store policy bypass and a potential MitM attack.
4) Improper validation of certificate with host mismatch (CVE-ID: CVE-2025-15079)
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists during SSH-based transfers due to the library mistakenly accepts connections to hosts not present in the specified file if they were added as recognized in the libssh global knownhosts file. A remote attacker can perform a MitM attack.
Note, the vulnerability affects libcurl builds that use libssh backend instead of libssh2.
5) Improper authentication (CVE-ID: CVE-2025-15224)
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error when doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication. In such case the curl would wrongly still ask and authenticate using a locally running SSH agent.
Note, the vulnerability affects libcurl builds that use libssh backend instead of libssh2.
Remediation
Install update from vendor's website.