SB2026090854 - SUSE update for curl



SB2026090854 - SUSE update for curl

Published: September 8, 2026 Updated: September 30, 2026

Security Bulletin ID SB2026090854
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 33% Low 67%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 vulnerabilities.


1) Improper restriction of communication channel to intended endpoints (CVE-ID: CVE-2026-13608)

CWE-ID: CWE-923 - Improper Restriction of Communication Channel to Intended Endpoints

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass LDAP server authentication.

The vulnerability exists due to improper restriction of communication channel to intended endpoints in the libcurl SASL negotiation for LDAP authentication when processing an incomplete OpenLDAP SASL handshake sequence. A remote attacker can inject a premature or shortcut response to bypass LDAP server authentication.

The issue only occurs when the OpenLDAP backend is used, and LDAPS is not affected.


2) Use-after-free (CVE-ID: CVE-2026-80229)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to use-after-free in libcurl multi interface connection reuse handling when performing transfers over pooled TLS connections with OpenSSL 3 providers. A remote user can trigger premature easy handle destruction during connection reuse to cause a denial of service.

This affects libcurl built with OpenSSL 3+ provider configurations and also impacts the curl command line tool.


3) Improper Certificate Validation (CVE-ID: CVE-2026-80230)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass public key pinning.

The vulnerability exists due to improper certificate validation in libcurl and the curl command line tool when establishing TLS connections with CURLOPT_PINNEDPUBLICKEY configured and peer and host verification disabled. A remote attacker can present a connection without a server certificate to bypass public key pinning.

This issue is present only when curl is built with OpenSSL or a fork such as BoringSSL, AWS-LC, LibreSSL, or QuicTLS, and the insecure configuration also permits certificate-less connections.


Remediation

Install update from vendor's website.