Opened 7 months ago

Closed 6 months ago

#22938 closed enhancement (fixed)

curl-8.19.0

Reported by: Joe Locash Owned by: zeckma
Priority: elevated Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

Changes: ​https://curl.se/changes.html

The following CVE's have been fixed:

  • CVE-2026-3805: use after free in SMB connection reuse
  • CVE-2026-3784: wrong proxy connection reuse with credentials
  • CVE-2026-3783: token leak with redirect and netrc
  • CVE-2026-1965: bad reuse of HTTP Negotiate connection

Change History (7)

comment:1 by Joe Locash, 7 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:2 by Joe Locash, 7 months ago

Fixed at 731bf6703b.

Leaving open for SA.

comment:3 by zeckma, 7 months ago

I'll handle the SA.

comment:4 by zeckma, 7 months ago

Owner: changed from Joe Locash to zeckma
Status: assigned → new

comment:5 by zeckma, 7 months ago

Status: new → assigned

comment:6 by zeckma, 6 months ago

Overall rating: Medium.

comment:7 by zeckma, 6 months ago

Resolution: → fixed
Status: assigned → closed

SA-13.0-009 issued.

Note: See TracTickets for help on using tickets.