This bug was fixed in the package curl - 8.18.0-1ubuntu2.7

---------------
curl (8.18.0-1ubuntu2.7) resolute-security; urgency=medium

  [ Charles Cochran ]
  * SECURITY UPDATE: Authentication bypass in LDAP SASL negotiation.
    - debian/patches/CVE-2026-13608.patch: openldap: handle
      Curl_sasl_continue() returns better in lib/openldap.c.
    - CVE-2026-13608
  * SECURITY UPDATE: Use after free in HTTP/2 server push.
    - debian/patches/CVE-2026-18924.patch: make server push transfers
      inherit share from parent in lib/http2.c.
    - CVE-2026-18924
  * SECURITY UPDATE: Use after free in OpenSSL library context.
    - debian/patches/CVE-2026-80229.patch: avoid conn reuse if provider is
      used in lib/vtls/openssl.c.
    - CVE-2026-80229
  * SECURITY UPDATE: Public key pinning bypass.
    - debian/patches/CVE-2026-80230.patch: require server cert if public
      key pinned in lib/vtls/openssl.c.
    - CVE-2026-80230
  * SECURITY UPDATE: Cookie Secure attribute bypass in Set-Cookie.
    - debian/patches/CVE-2026-80255.patch: improve TAB handling in
      lib/cookie.c, tests/data/Makefile.am, tests/data/test2885.
    - CVE-2026-80255
  * SECURITY UPDATE: Cookie injection for public suffix domains.
    - debian/patches/CVE-2026-82209.patch: ensure cookies set for an exact
      PSL domain are host-only in lib/cookie.c, tests/data/Makefile.am,
      tests/data/test1136, tests/data/test2318, tests/data/test798.
    - CVE-2026-82209
  * SECURITY REGRESSION: CVE-2026-9080: upstream pt 2 needed (LP: #2167969)
    - debian/patches/CVE-2026-9080-post1.patch: multi_ev: refresh sock
      entry after remove callback in lib/multi_ev.c.

  [ Kyle Kernick ]
  * SECURITY REGRESSION: checksrc errors and failing test case for
    CVE-2026-8927 (LP #2167779)
    - debian/patches/CVE-2026-11856.patch: Use curlx_strdup to fix
      autopkgtests
    - debian/patches/CVE-2026-8458.patch: Wrap long lines and remove unused
      variable to fix autopkgtests
    - debian/patches/CVE-2026-8927.patch: Fix failing test

 -- Charles Cochran <[email protected]>  Fri, 18 Sep 2026
14:17:09 -0400

** Changed in: curl (Ubuntu)
       Status: New => Fix Released

** CVE added: https://cve.org/CVERecord?id=CVE-2026-11856

** CVE added: https://cve.org/CVERecord?id=CVE-2026-13608

** CVE added: https://cve.org/CVERecord?id=CVE-2026-18924

** CVE added: https://cve.org/CVERecord?id=CVE-2026-80229

** CVE added: https://cve.org/CVERecord?id=CVE-2026-80230

** CVE added: https://cve.org/CVERecord?id=CVE-2026-80255

** CVE added: https://cve.org/CVERecord?id=CVE-2026-82209

** CVE added: https://cve.org/CVERecord?id=CVE-2026-8458

** CVE added: https://cve.org/CVERecord?id=CVE-2026-8927

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2167969

Title:
  Upstream update to CVE-2026-9080 fix missing in Resolute

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/curl/+bug/2167969/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to