Use of insufficiently random values in cURL - CVE-2025-10148

 

Use of insufficiently random values in cURL - CVE-2025-10148

Published: September 10, 2025


Vulnerability identifier: #VU115137
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N]
CVE-ID: CVE-2025-10148
CWE-ID: CWE-330
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform cache poisoning. 

The vulnerability exists due to the websocket code does not update the 32 bit mask pattern for each new outgoing frame as the specification says.Instead it used a fixed mask that persisted and was used throughout the entire connection. As a result, a malicious server can induce traffic between the two communicating parties that can be interpreted by an involved proxy and poison cached content. 


Affected software

cURL
SUSE Linux Enterprise Server 15 SP4
SUSE Manager Proxy 4.3
SUSE Manager Retail Branch Server 4.3
SUSE Linux Enterprise Server 15 SP5
SUSE Manager Server 4.3
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Real Time 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Ubuntu
Basesystem Module
openSUSE Leap
Fedora
Tenable Identity Exposure (formerly Tenable.ad)
EasyApache
Nessus Network Monitor
IBM Cloud Pak for Multicloud Management
LANTIME Operating System Firmware (LTOS)
libbrotlienc1-debuginfo
libbrotlidec1-debuginfo
brotli-debugsource
libbrotlidec1
libbrotlidec1-32bit
libbrotlicommon1-32bit
libbrotlienc1-32bit-debuginfo
libbrotlicommon1-32bit-debuginfo
libbrotlidec1-32bit-debuginfo
libbrotlienc1-32bit
libbrotlicommon1-debuginfo
libbrotli-devel
libbrotlienc1
libbrotlicommon1
brotli
brotli-debuginfo
curl (Ubuntu package)
libcurl4
curl-debugsource
libcurl4-debuginfo-32bit
libcurl4-32bit
libcurl-devel
curl-debuginfo
libcurl4-debuginfo
curl
libcurl4-32bit-debuginfo
libcurl4-64bit
curl-mini-debugsource
libcurl-mini4-debuginfo
libcurl-mini4
curl-zsh-completion
curl-fish-completion
libcurl-devel-doc
libcurl-devel-32bit
libcurl-devel-64bit
libcurl4-64bit-debuginfo

How to mitigate CVE-2025-10148

Install updates from vendor's website.

cURL - update to 8.16.0
Tenable Identity Exposure (formerly Tenable.ad) - update to 3.77.14
EasyApache - update to 4 25-28
Nessus Network Monitor - update to 6.5.3
LANTIME Operating System Firmware (LTOS) - update to 7.10.004
libbrotlienc1-debuginfo - update to 1.0.7-150200.3.5.1
libbrotlidec1-debuginfo - update to 1.0.7-150200.3.5.1
brotli-debugsource - update to 1.0.7-150200.3.5.1
libbrotlidec1 - update to 1.0.7-150200.3.5.1
libbrotlidec1-32bit - update to 1.0.7-150200.3.5.1
libbrotlicommon1-32bit - update to 1.0.7-150200.3.5.1
libbrotlienc1-32bit-debuginfo - update to 1.0.7-150200.3.5.1
libbrotlicommon1-32bit-debuginfo - update to 1.0.7-150200.3.5.1
libbrotlidec1-32bit-debuginfo - update to 1.0.7-150200.3.5.1
libbrotlienc1-32bit - update to 1.0.7-150200.3.5.1
libbrotlicommon1-debuginfo - update to 1.0.7-150200.3.5.1
libbrotli-devel - update to 1.0.7-150200.3.5.1
libbrotlienc1 - update to 1.0.7-150200.3.5.1
libbrotlicommon1 - update to 1.0.7-150200.3.5.1
brotli - update to 1.0.7-150200.3.5.1
brotli-debuginfo - update to 1.0.7-150200.3.5.1
IBM Cloud Pak for Multicloud Management - update to 2.3 Fix Pack 12
curl (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm19, 7.47.0-1ubuntu2.19+esm15, 7.58.0-2ubuntu3.24+esm7, 7.68.0-1ubuntu2.25+esm2, 7.81.0-1ubuntu1.22, 8.5.0-2ubuntu10.7, 8.14.1-2ubuntu1.1
libcurl4 - addressed in versions 8.0.1-11.108.1, 8.14.1-150200.4.91.1, 8.14.1-150400.5.69.1, 8.14.1-150600.4.28.1
curl-debugsource - addressed in versions 8.0.1-11.108.1, 8.14.1-150200.4.91.1, 8.14.1-150400.5.69.1, 8.14.1-150600.4.28.1
libcurl4-debuginfo-32bit - update to 8.0.1-11.108.1
libcurl4-32bit - addressed in versions 8.0.1-11.108.1, 8.14.1-150200.4.91.1, 8.14.1-150400.5.69.1, 8.14.1-150600.4.28.1
libcurl-devel - addressed in versions 8.0.1-11.108.1, 8.14.1-150200.4.91.1, 8.14.1-150400.5.69.1, 8.14.1-150600.4.28.1
curl-debuginfo - addressed in versions 8.0.1-11.108.1, 8.14.1-150200.4.91.1, 8.14.1-150400.5.69.1, 8.14.1-150600.4.28.1
libcurl4-debuginfo - addressed in versions 8.0.1-11.108.1, 8.14.1-150200.4.91.1, 8.14.1-150400.5.69.1, 8.14.1-150600.4.28.1
curl - addressed in versions 8.0.1-11.108.1, 8.14.1-150200.4.91.1, 8.14.1-150400.5.69.1, 8.14.1-150600.4.28.1
curl - update to 8.11.1-6.fc42
libcurl4-32bit-debuginfo - addressed in versions 8.14.1-150200.4.91.1, 8.14.1-150400.5.69.1, 8.14.1-150600.4.28.1
libcurl4-64bit - addressed in versions 8.14.1-150400.5.69.1, 8.14.1-150600.4.28.1
curl-mini-debugsource - addressed in versions 8.14.1-150400.5.69.1, 8.14.1-150600.4.28.1
libcurl-mini4-debuginfo - addressed in versions 8.14.1-150400.5.69.1, 8.14.1-150600.4.28.1
libcurl-mini4 - addressed in versions 8.14.1-150400.5.69.1, 8.14.1-150600.4.28.1
curl-zsh-completion - addressed in versions 8.14.1-150400.5.69.1, 8.14.1-150600.4.28.1
curl-fish-completion - addressed in versions 8.14.1-150400.5.69.1, 8.14.1-150600.4.28.1
libcurl-devel-doc - addressed in versions 8.14.1-150400.5.69.1, 8.14.1-150600.4.28.1
libcurl-devel-32bit - addressed in versions 8.14.1-150400.5.69.1, 8.14.1-150600.4.28.1
libcurl-devel-64bit - addressed in versions 8.14.1-150400.5.69.1, 8.14.1-150600.4.28.1
libcurl4-64bit-debuginfo - addressed in versions 8.14.1-150400.5.69.1, 8.14.1-150600.4.28.1

External References

Related Security Bulletins