curl regression
Multiple vulnerabilities in curl affecting various Ubuntu LTS and interim releases were addressed in update USN-8487-2. These include issues with connection reuse during STARTTLS upgrades, incorrect connection reuse for Negotiate authentication, improper cookie parsing, double-free leading to potential code execution, .netrc password selection errors, proxy authentication state leaks, use-after-free in event callbacks, early TLS data transmission without certificate verification, and SSH host key type mismatches. The update fixes an incomplete prior patch for CVE-2026-8927. These issues could allow remote attackers to cause denial of service, access sensitive information, or impersonate trusted servers.
AI Analysis
Technical Summary
The USN-8487-2 update for curl addresses multiple security vulnerabilities originally fixed in USN-8487-1 but incompletely patched for CVE-2026-8927. Vulnerabilities include improper reuse of live connections during STARTTLS upgrades (CVE-2026-8286), incorrect reuse of connections for Negotiate authentication across different services (CVE-2026-8458), flawed cookie parsing allowing setting cookies for unrelated domains (CVE-2026-8924), double-free of GSASL context causing potential denial of service or code execution (CVE-2026-8925), incorrect password selection from .netrc files (CVE-2026-8926), failure to clear proxy authentication state leading to credential exposure (CVE-2026-8927 and CVE-2026-9079), use-after-free in event-based socket callbacks (CVE-2026-9080), sending early TLS data before certificate verification (CVE-2026-9545), and improper rejection of SSH host key type mismatches enabling impersonation (CVE-2026-9547). These vulnerabilities affect multiple Ubuntu versions including 16.04 LTS through 26.04 LTS and some interim releases. The update fully resolves these issues.
Potential Impact
Remote attackers could exploit these vulnerabilities to cause denial of service, execute arbitrary code, access sensitive credentials, impersonate trusted servers, or cause curl to use unintended TLS configurations. Some issues allow cross-service credential leakage or cookie setting for unrelated domains, potentially compromising security boundaries. The vulnerabilities affect multiple Ubuntu LTS and interim releases, impacting systems using vulnerable curl versions.
Mitigation Recommendations
An official fix is available in update USN-8487-2. Users should apply this update promptly to fully remediate the vulnerabilities, including the incomplete fix for CVE-2026-8927. No additional mitigation actions are required beyond applying the vendor-provided patch.
curl regression
Description
Multiple vulnerabilities in curl affecting various Ubuntu LTS and interim releases were addressed in update USN-8487-2. These include issues with connection reuse during STARTTLS upgrades, incorrect connection reuse for Negotiate authentication, improper cookie parsing, double-free leading to potential code execution, .netrc password selection errors, proxy authentication state leaks, use-after-free in event callbacks, early TLS data transmission without certificate verification, and SSH host key type mismatches. The update fixes an incomplete prior patch for CVE-2026-8927. These issues could allow remote attackers to cause denial of service, access sensitive information, or impersonate trusted servers.
Affected software
pkg:deb/ubuntu/curl?arch=source&distro=esm-infra-legacy/trustyRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The USN-8487-2 update for curl addresses multiple security vulnerabilities originally fixed in USN-8487-1 but incompletely patched for CVE-2026-8927. Vulnerabilities include improper reuse of live connections during STARTTLS upgrades (CVE-2026-8286), incorrect reuse of connections for Negotiate authentication across different services (CVE-2026-8458), flawed cookie parsing allowing setting cookies for unrelated domains (CVE-2026-8924), double-free of GSASL context causing potential denial of service or code execution (CVE-2026-8925), incorrect password selection from .netrc files (CVE-2026-8926), failure to clear proxy authentication state leading to credential exposure (CVE-2026-8927 and CVE-2026-9079), use-after-free in event-based socket callbacks (CVE-2026-9080), sending early TLS data before certificate verification (CVE-2026-9545), and improper rejection of SSH host key type mismatches enabling impersonation (CVE-2026-9547). These vulnerabilities affect multiple Ubuntu versions including 16.04 LTS through 26.04 LTS and some interim releases. The update fully resolves these issues.
Potential Impact
Remote attackers could exploit these vulnerabilities to cause denial of service, execute arbitrary code, access sensitive credentials, impersonate trusted servers, or cause curl to use unintended TLS configurations. Some issues allow cross-service credential leakage or cookie setting for unrelated domains, potentially compromising security boundaries. The vulnerabilities affect multiple Ubuntu LTS and interim releases, impacting systems using vulnerable curl versions.
Mitigation Recommendations
An official fix is available in update USN-8487-2. Users should apply this update promptly to fully remediate the vulnerabilities, including the incomplete fix for CVE-2026-8927. No additional mitigation actions are required beyond applying the vendor-provided patch.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- USN-8487-2
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS"]
Patch Information
Threat ID: 6abb4194f7a7c54106cc380c
Added to database: 09/29/2026, 04:41:56 UTC
Last enriched: 09/29/2026, 04:51:47 UTC
Last updated: 09/29/2026, 10:27:16 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.