Double free in cURL - CVE-2026-8925
Published: June 24, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to double free in the SASL authentication logic when processing SASL authentication with a malicious server response. A remote user can influence server behavior to trigger the double free and cause a denial of service.
Only builds using libgsasl are vulnerable, and the issue can be triggered over IMAP, POP3, and SMTP.
Affected software
LANTIME Operating System Firmware (LTOS)
Ubuntu
openEuler
Fedora
curl (Ubuntu package)
curl-debugsource
libcurl
libcurl-devel
curl-help
curl-debuginfo
curl
How to mitigate CVE-2026-8925
LANTIME Operating System Firmware (LTOS) - update to 7.10.013
curl (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm20, 7.35.0-1ubuntu2.20+esm23, 7.47.0-1ubuntu2.19+esm16, 7.58.0-2ubuntu3.24+esm9, 7.68.0-1ubuntu2.25+esm4, 7.81.0-1ubuntu1.25, 8.5.0-2ubuntu10.10, 8.14.1-2ubuntu1.4, 8.18.0-1ubuntu2.2
curl-debugsource - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
libcurl - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
libcurl-devel - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
curl-help - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
curl-debuginfo - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
curl - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-35
curl - addressed in versions 8.15.0-9.fc43, 8.18.0-9.fc44
External References
Related Security Bulletins
- Multiple vulnerabilities in cURL
- Ubuntu update for curl
- Multiple vulnerabilities in Meinberg LANTIME firmware
- Fedora 44 update for curl
- Fedora 43 update for curl
- openEuler 24.03 LTS SP3 update for curl
- openEuler 24.03 LTS SP1 update for curl
- openEuler 22.03 LTS SP4 update for curl
- openEuler 20.03 LTS SP4 update for curl
- openEuler 24.03 LTS SP4 update for curl
- Ubuntu update for curl