CVE-2026-8925

Name
CVE-2026-8925
Description
The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
2499f714-1537-4658-8207-48ae4bb9eae9 https://curl.se/docs/CVE-2026-8925.html
2499f714-1537-4658-8207-48ae4bb9eae9 https://curl.se/docs/CVE-2026-8925.json
2499f714-1537-4658-8207-48ae4bb9eae9 https://hackerone.com/reports/3735193

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* curl >= 8.15.0 < 8.21.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
curl edge-main 8.21.0-r0 Achill Gilgenast <achill@achill.org> fixed
curl edge-main 8.20.0-r1 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl edge-main 8.20.0-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl edge-main 8.19.0-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl edge-main 8.18.0-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl edge-main 8.17.0-r1 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl edge-main 8.17.0-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl edge-main 8.16.0-r2 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl edge-main 8.16.0-r1 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl edge-main 8.16.0-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl edge-main 8.15.0-r2 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl edge-main 8.15.0-r1 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl edge-main 8.15.0-r0 fossdd <fossdd@pwned.life> possibly vulnerable
curl 3.24-main 8.21.0-r0 Achill Gilgenast <achill@achill.org> fixed
curl 3.24-main 8.20.0-r1 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl 3.23-main 8.19.0-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
curl 3.23-main 8.17.0-r1 Achill Gilgenast <achill@achill.org> possibly vulnerable