This bug was fixed in the package curl - 8.18.0-1ubuntu2.7
---------------
curl (8.18.0-1ubuntu2.7) resolute-security; urgency=medium
[ Charles Cochran ]
* SECURITY UPDATE: Authentication bypass in LDAP SASL negotiation.
- debian/patches/CVE-2026-13608.patch: openldap: handle
Curl_sasl_continue() returns better in lib/openldap.c.
- CVE-2026-13608
* SECURITY UPDATE: Use after free in HTTP/2 server push.
- debian/patches/CVE-2026-18924.patch: make server push transfers
inherit share from parent in lib/http2.c.
- CVE-2026-18924
* SECURITY UPDATE: Use after free in OpenSSL library context.
- debian/patches/CVE-2026-80229.patch: avoid conn reuse if provider is
used in lib/vtls/openssl.c.
- CVE-2026-80229
* SECURITY UPDATE: Public key pinning bypass.
- debian/patches/CVE-2026-80230.patch: require server cert if public
key pinned in lib/vtls/openssl.c.
- CVE-2026-80230
* SECURITY UPDATE: Cookie Secure attribute bypass in Set-Cookie.
- debian/patches/CVE-2026-80255.patch: improve TAB handling in
lib/cookie.c, tests/data/Makefile.am, tests/data/test2885.
- CVE-2026-80255
* SECURITY UPDATE: Cookie injection for public suffix domains.
- debian/patches/CVE-2026-82209.patch: ensure cookies set for an exact
PSL domain are host-only in lib/cookie.c, tests/data/Makefile.am,
tests/data/test1136, tests/data/test2318, tests/data/test798.
- CVE-2026-82209
* SECURITY REGRESSION: CVE-2026-9080: upstream pt 2 needed (LP: #2167969)
- debian/patches/CVE-2026-9080-post1.patch: multi_ev: refresh sock
entry after remove callback in lib/multi_ev.c.
[ Kyle Kernick ]
* SECURITY REGRESSION: checksrc errors and failing test case for
CVE-2026-8927 (LP #2167779)
- debian/patches/CVE-2026-11856.patch: Use curlx_strdup to fix
autopkgtests
- debian/patches/CVE-2026-8458.patch: Wrap long lines and remove unused
variable to fix autopkgtests
- debian/patches/CVE-2026-8927.patch: Fix failing test
-- Charles Cochran <[email protected]> Fri, 18 Sep 2026
14:17:09 -0400
** Changed in: curl (Ubuntu)
Status: New => Fix Released
** CVE added: https://cve.org/CVERecord?id=CVE-2026-11856
** CVE added: https://cve.org/CVERecord?id=CVE-2026-13608
** CVE added: https://cve.org/CVERecord?id=CVE-2026-18924
** CVE added: https://cve.org/CVERecord?id=CVE-2026-80229
** CVE added: https://cve.org/CVERecord?id=CVE-2026-80230
** CVE added: https://cve.org/CVERecord?id=CVE-2026-80255
** CVE added: https://cve.org/CVERecord?id=CVE-2026-82209
** CVE added: https://cve.org/CVERecord?id=CVE-2026-8458
** CVE added: https://cve.org/CVERecord?id=CVE-2026-8927
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2167969
Title:
Upstream update to CVE-2026-9080 fix missing in Resolute
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/curl/+bug/2167969/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs