ZeroHour
Ubuntu Security Noticespublished ()ingested

USN-8670-3: curl vulnerability

lowAdvisoryimportance 22
AI summary · glm-5.3-flash

Ubuntu issued USN-8670-3 updating curl for Ubuntu 26.04 LTS to fix a flaw where wrong client certificates could be used on reused connections.

Ubuntu Security Notice USN-8670-3 extends the curl fix from USN-8670-1 to Ubuntu 26.04 LTS. The flaw, discovered by Joshua Rogers, involves incorrect handling of connection reuse when client certificate settings change, potentially causing the wrong client certificate to be presented. The issue can lead to authentication mix-ups rather than remote code execution.

  • Update for Ubuntu 26.04 LTS following earlier USN-8670-1
  • Connection reuse with changed client certificate settings mishandled
  • Impact is wrong-certificate use, not code execution
Full article

USN-8670-1 fixed a vulnerability in curl. This update provides the corresponding update for Ubuntu 26.04 LTS. Original advisory details: Joshua Rogers discovered that curl incorrectly handled reusing connections when client certificate settings changed. This could result in the wrong client certificates being used, contrary to expectations.

This source does not provide full text. Read it at ubuntu.com.