[ubuntu/questing-security] curl 8.14.1-2ubuntu1.4 (Accepted)

Kyle Kernick kyle.kernick at canonical.com
Tue Jun 30 21:20:13 UTC 2026


curl (8.14.1-2ubuntu1.4) questing-security; urgency=medium

  * SECURITY UPDATE: Connection reuse for starttls protocols.
    - debian/patches/CVE-2026-8286.patch: When a connection is tested for
      reuse in a transfer that may upgrade to TLS (commonly via STARTTLS),
      the SSL configuration must match the existing connection in lib/url.c
    - CVE-2026-8286
  * SECURITY UPDATE: Connection reuse in SASL.
    - debian/patches/CVE-2026-8458.patch: Fix erroneous connection reuse in
      in lib/curl_sasl.c, lib/http_negotiate.c, lib/http_ntlm.c, lib/imap.c,
      lib/openldap.c, and lib/pop3.c
    - CVE-2026-8458
  * SECURITY UPDATE: Cookie injection in is_public_suffix.
    - debian/patches/CVE-2026-8924.patch: Trim trailing dots when checking
      PSL in lib/cookie.c.
    - CVE-2026-8924
  * SECURITY UPDATE: Double-free in gsasl.
    - debian/patches/CVE-2026-8925.patch: Require libgasl 1.6.0 to handle
      NULL argument in lib/vauth/gsasl.c.
    - CVE-2026-8925
  * SECURITY UPDATE: Information disclosure in netrc.
    - debian/patches/CVE-2026-8926.patch: Do not return a password from
      parsenetrc() when the requested login did not match the credentials
      found for the matched machine in lib/netrc.c.
    - CVE-2026-8926
  * SECURITY UPDATE: Information disclosure in libcurl
    - debian/patches/CVE-2026-8927.patch: Detect if proxy is not the same as
      previous and flush state in lib/url.c and lib/urldata.h.
    - debian/patches/CVE-2026-9079.patch: Verify NULLed proxy credentials
      in lib/setopt.c.
    - debian/patches/CVE-2026-9545.patch: Hard fail when certificate
      verification fails in lib/vquic/curl_ngtcp2.c.
    - CVE-2026-8927
    - CVE-2026-9079
    - CVE-2026-9545
  * SECURITY UPDATE: Use-after-free in curl_easy_parse
    - debian/patches/CVE-2026-9080.patch: Introduce magic struct field to
      assert against NULL pointers in lib/multi_ev.c
    - CVE-2026-9080
  * SECURITY UPDATE: Man-in-the-middle in libcurl.
    - debian/patches/CVE-2026-9547.patch: Reject host key mismatches in
      in lib/vssh/libssh.c
    - CVE-2026-9547

Date: 2026-06-30 00:10:12.802990+00:00
Changed-By: Kyle Kernick <kyle.kernick at canonical.com>
https://launchpad.net/ubuntu/+source/curl/8.14.1-2ubuntu1.4
-------------- next part --------------
Sorry, changesfile not available.


More information about the Questing-changes mailing list