CVE-2026-8925

Discovered by AISLEPUBLISHEDCWE-415

Description

The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.

CVSS Base Scores

CVSS v3.1(Primary)
9.8

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionStatus
curlcurl8.15.0affected
curlcurl8.17.0affected
curlcurlab650379a8c25ca952f651476d25b4cdd77bb3fcaffected
curlcurl8.20.0affected
curlcurl8.19.0affected
curlcurl8.18.0affected
curlcurl8.17.0affected
curlcurl8.16.0affected
curlcurl8.15.0affected

Credits

  • Joshua Rogers (Aisle Research)(finder)
  • Viktor Szakats(remediation developer)

References