[ubuntu/resolute-updates] curl 8.18.0-1ubuntu2.7 (Accepted)

Ubuntu Archive Robot ubuntu-archive-robot at lists.canonical.com
Thu Sep 24 19:01:25 UTC 2026


curl (8.18.0-1ubuntu2.7) resolute-security; urgency=medium

  [ Charles Cochran ]
  * SECURITY UPDATE: Authentication bypass in LDAP SASL negotiation.
    - debian/patches/CVE-2026-13608.patch: openldap: handle
      Curl_sasl_continue() returns better in lib/openldap.c.
    - CVE-2026-13608
  * SECURITY UPDATE: Use after free in HTTP/2 server push.
    - debian/patches/CVE-2026-18924.patch: make server push transfers
      inherit share from parent in lib/http2.c.
    - CVE-2026-18924
  * SECURITY UPDATE: Use after free in OpenSSL library context.
    - debian/patches/CVE-2026-80229.patch: avoid conn reuse if provider is
      used in lib/vtls/openssl.c.
    - CVE-2026-80229
  * SECURITY UPDATE: Public key pinning bypass.
    - debian/patches/CVE-2026-80230.patch: require server cert if public
      key pinned in lib/vtls/openssl.c.
    - CVE-2026-80230
  * SECURITY UPDATE: Cookie Secure attribute bypass in Set-Cookie.
    - debian/patches/CVE-2026-80255.patch: improve TAB handling in
      lib/cookie.c, tests/data/Makefile.am, tests/data/test2885.
    - CVE-2026-80255
  * SECURITY UPDATE: Cookie injection for public suffix domains.
    - debian/patches/CVE-2026-82209.patch: ensure cookies set for an exact
      PSL domain are host-only in lib/cookie.c, tests/data/Makefile.am,
      tests/data/test1136, tests/data/test2318, tests/data/test798.
    - CVE-2026-82209
  * SECURITY REGRESSION: CVE-2026-9080: upstream pt 2 needed (LP: #2167969)
    - debian/patches/CVE-2026-9080-post1.patch: multi_ev: refresh sock
      entry after remove callback in lib/multi_ev.c.

  [ Kyle Kernick ]
  * SECURITY REGRESSION: checksrc errors and failing test case for
    CVE-2026-8927 (LP #2167779)
    - debian/patches/CVE-2026-11856.patch: Use curlx_strdup to fix
      autopkgtests
    - debian/patches/CVE-2026-8458.patch: Wrap long lines and remove unused
      variable to fix autopkgtests
    - debian/patches/CVE-2026-8927.patch: Fix failing test

Date: 2026-09-23 20:16:38.311574+00:00
Changed-By: Charles Cochran <charles.cochran at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/curl/8.18.0-1ubuntu2.7
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list