Double free in cURL - CVE-2026-8925

 

Double free in cURL - CVE-2026-8925

Published: June 24, 2026


Vulnerability identifier: #VU135083
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-8925
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to double free in the SASL authentication logic when processing SASL authentication with a malicious server response. A remote user can influence server behavior to trigger the double free and cause a denial of service.

Only builds using libgsasl are vulnerable, and the issue can be triggered over IMAP, POP3, and SMTP.


Affected software

cURL
LANTIME Operating System Firmware (LTOS)
Ubuntu
curl (Ubuntu package)

How to mitigate CVE-2026-8925

Install security update from vendor's website.

cURL - update to 8.21.0
LANTIME Operating System Firmware (LTOS) - update to 7.10.013
curl (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm20, 7.47.0-1ubuntu2.19+esm16, 7.58.0-2ubuntu3.24+esm9, 7.68.0-1ubuntu2.25+esm4, 7.81.0-1ubuntu1.25, 8.5.0-2ubuntu10.10, 8.14.1-2ubuntu1.4, 8.18.0-1ubuntu2.2

External References

Related Security Bulletins