[ubuntu/resolute-updates] curl 8.18.0-1ubuntu2.7 (Accepted)
Ubuntu Archive Robot
ubuntu-archive-robot at lists.canonical.com
Thu Sep 24 19:01:25 UTC 2026
curl (8.18.0-1ubuntu2.7) resolute-security; urgency=medium
[ Charles Cochran ]
* SECURITY UPDATE: Authentication bypass in LDAP SASL negotiation.
- debian/patches/CVE-2026-13608.patch: openldap: handle
Curl_sasl_continue() returns better in lib/openldap.c.
- CVE-2026-13608
* SECURITY UPDATE: Use after free in HTTP/2 server push.
- debian/patches/CVE-2026-18924.patch: make server push transfers
inherit share from parent in lib/http2.c.
- CVE-2026-18924
* SECURITY UPDATE: Use after free in OpenSSL library context.
- debian/patches/CVE-2026-80229.patch: avoid conn reuse if provider is
used in lib/vtls/openssl.c.
- CVE-2026-80229
* SECURITY UPDATE: Public key pinning bypass.
- debian/patches/CVE-2026-80230.patch: require server cert if public
key pinned in lib/vtls/openssl.c.
- CVE-2026-80230
* SECURITY UPDATE: Cookie Secure attribute bypass in Set-Cookie.
- debian/patches/CVE-2026-80255.patch: improve TAB handling in
lib/cookie.c, tests/data/Makefile.am, tests/data/test2885.
- CVE-2026-80255
* SECURITY UPDATE: Cookie injection for public suffix domains.
- debian/patches/CVE-2026-82209.patch: ensure cookies set for an exact
PSL domain are host-only in lib/cookie.c, tests/data/Makefile.am,
tests/data/test1136, tests/data/test2318, tests/data/test798.
- CVE-2026-82209
* SECURITY REGRESSION: CVE-2026-9080: upstream pt 2 needed (LP: #2167969)
- debian/patches/CVE-2026-9080-post1.patch: multi_ev: refresh sock
entry after remove callback in lib/multi_ev.c.
[ Kyle Kernick ]
* SECURITY REGRESSION: checksrc errors and failing test case for
CVE-2026-8927 (LP #2167779)
- debian/patches/CVE-2026-11856.patch: Use curlx_strdup to fix
autopkgtests
- debian/patches/CVE-2026-8458.patch: Wrap long lines and remove unused
variable to fix autopkgtests
- debian/patches/CVE-2026-8927.patch: Fix failing test
Date: 2026-09-23 20:16:38.311574+00:00
Changed-By: Charles Cochran <charles.cochran at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.7
-------------- next part --------------
Sorry, changesfile not available.
More information about the Resolute-changes
mailing list