Double free in cURL - CVE-2026-8925
Published: June 24, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to double free in the SASL authentication logic when processing SASL authentication with a malicious server response. A remote user can influence server behavior to trigger the double free and cause a denial of service.
Only builds using libgsasl are vulnerable, and the issue can be triggered over IMAP, POP3, and SMTP.
Affected software
LANTIME Operating System Firmware (LTOS)
Ubuntu
curl (Ubuntu package)
How to mitigate CVE-2026-8925
LANTIME Operating System Firmware (LTOS) - update to 7.10.013
curl (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm20, 7.47.0-1ubuntu2.19+esm16, 7.58.0-2ubuntu3.24+esm9, 7.68.0-1ubuntu2.25+esm4, 7.81.0-1ubuntu1.25, 8.5.0-2ubuntu10.10, 8.14.1-2ubuntu1.4, 8.18.0-1ubuntu2.2