Opened 9 months ago

Closed 9 months ago

Last modified 8 months ago

#22618 closed enhancement (fixed)

curl-8.18.0

Reported by: Joe Locash Owned by: zeckma
Priority: elevated Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New minor release.

Changelog: ​https://curl.se/ch/

This release fixes 6 CVE's:

  • CVE-2025-15224: libssh key passphrase bypass without agent set

​https://curl.se/docs/CVE-2025-15224.html

  • CVE-2025-15079: libssh global known_hosts override

​https://curl.se/docs/CVE-2025-15079.html

  • CVE-2025-14819: OpenSSL partial chain store policy bypass

​https://curl.se/docs/CVE-2025-14819.html

  • CVE-2025-14524: bearer token leak on cross-protocol redirect

​https://curl.se/docs/CVE-2025-14524.html

  • CVE-2025-14017: broken TLS options for threaded LDAPS

​https://curl.se/docs/CVE-2025-14017.html

  • CVE-2025-13034: No QUIC certificate pinning with GnuTLS

​https://curl.se/docs/CVE-2025-13034.html

Change History (12)

comment:1 by Xi Ruoyao, 9 months ago

AFAIK BLFS does not have libssh (not libssh2: they are different packages) and QUIC support at all. Thus I'm unsure if we should mention those three in SA.

Last edited 9 months ago by Xi Ruoyao (previous) (diff)

comment:2 by Douglas R. Reno, 9 months ago

Looking at this a bit deeper, I think the only vulnerability that we're vulnerable to is CVE-2025-14819 in our default configuration, though some users might get hit by CVE-2025-13034. We use OpenLDAP for LDAP support, so as far as I know we shouldn't be affected by CVE-2025-14017. We could theoretically also get hit by CVE-2025-14524 but I don't know of any normal use cases that we have that use OAuth2 tokens

comment:3 by Bruce Dubbs, 9 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:4 by zeckma, 9 months ago

I'll handle the security advisory for this ticket.

comment:5 by Bruce Dubbs, 9 months ago

It's hard for me to understand why there are over 400 changes to a package that has been around as long as this one. The previous release was November 2025. Perhaps they are trying to do too much in one application.

comment:6 by Bruce Dubbs, 9 months ago

Fixed at commits

c6fbfb3662 Update to poppler-26.01.0.
05ad7dbebc Update to curl-8.18.0 (Security Update).
e9ec3d89ff Update to libtasn1-4.21.0 (Security Update).
d939395a16 Update to libjpeg-turbo-3.1.3.

comment:7 by Bruce Dubbs, 9 months ago

Owner: changed from Bruce Dubbs to zeckma
Status: assigned → new

Leaving open for security advisory. Reassigning.

comment:8 by zeckma, 9 months ago

Status: new → assigned

comment:9 by zeckma, 9 months ago

Thanks for not closing the security tickets before SA filing. It's appreciated!

comment:10 by zeckma, 9 months ago

Highest rating is medium.

comment:11 by zeckma, 9 months ago

Resolution: → fixed
Status: assigned → closed

SA-12.4-068 issued.

comment:12 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.