SB2026093084 - Fedora 45 update for curl
Published: September 30, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Use-after-free (CVE-ID: CVE-2026-18924)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger a use-after-free.
The vulnerability exists due to use-after-free in libcurl HTTP/2 server push stream handling when processing an HTTPS HTTP/2 server push on a shared connection. A remote attacker can send a server push response sequence to trigger a use-after-free.
The issue affects libcurl only and requires HTTP/2 server push to be enabled and accepted by the application, along with connection sharing.
2) Exposure of Data Element to Wrong Session (CVE-ID: CVE-2026-19931)
CWE-ID: CWE-488 - Exposure of Data Element to Wrong Session
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause requests to be sent over another user's previously authenticated connection.
The vulnerability exists due to exposure of data element to wrong session in HTTP connection reuse for Negotiate authentication when reusing a connection established with empty credentials. A remote user can issue a request using blank credentials to cause requests to be sent over another user's previously authenticated connection.
This issue affects libcurl and the curl command line tool when Negotiate authentication is used with ambient credentials provided by SSPI or GSSAPI.
Remediation
Install update from vendor's website.