Ubuntu issues two late-September curl security notices
Ubuntu published USN-8820-1 and USN-8487-2 for curl flaws involving LDAP checks, HTTP/2 crashes, and connection reuse.
Ubuntu Security Notice USN-8820-1, dated 2026-09-24, covers several curl vulnerabilities. CVE-2026-13608, reported by Eunsoo Kim, involves incorrect SASL negotiation during LDAP authentication that a machine-in-the-middle attacker could use to bypass peer validation, and it affects only Ubuntu 24.04 LTS and 26.04 LTS. CVE-2026-18924, reported by Stephan Zeisberg, concerns mishandled HTTP/2 server-push streams on shared connections that a remote attacker could use to crash curl or possibly execute arbitrary code. Stanislav Fort also reported incorrect lifetime management of pooled TLS connections in curl's multi interface, but the published notice text is truncated and no CVE identifier is given for that issue. Separately, USN-8487-2, dated 2026-09-28, corrects an incomplete fix for CVE-2026-8927 shipped in USN-8487-1, and describes CVE-2026-8286, in which curl can reuse a live STARTTLS connection despite mismatched TLS settings, plus a further flaw that reuses Negotiate-authenticated connections across different services. The notices do not contradict each other; they document different curl issues, and no in-the-wild exploitation is reported for the USN-8487-2 issues.
- USN-8820-1 (2026-09-24) covers curl flaws CVE-2026-13608 and CVE-2026-18924.
- CVE-2026-13608 (Eunsoo Kim): incorrect LDAP SASL negotiation may let a machine-in-the-middle attacker bypass peer validation; it affects only Ubuntu 24.04 LTS and 26.04 LTS.
- CVE-2026-18924 (Stephan Zeisberg): mishandled HTTP/2 server-push streams on shared connections may let a remote attacker crash curl or possibly execute arbitrary code.
- Stanislav Fort reported incorrect lifetime management of pooled TLS connections in curl's multi interface; the USN-8820-1 text is truncated and gives no CVE for that issue.
- USN-8487-2 (2026-09-28) corrects an incomplete fix for CVE-2026-8927 that shipped in USN-8487-1.
- CVE-2026-8286 can reuse a live connection during STARTTLS upgrades even when the TLS configuration does not match, potentially forcing an unintended TLS setup.
- A separate flaw reuses Negotiate-authenticated connections across different services, which a remote attacker could possibly use to reach resources authenticated for another service.
- No in-the-wild exploitation is reported for the issues addressed by USN-8487-2.
Coverage timelineoldest first · each row is one article
- · 5d agoUSN-8820-1: curl vulnerabilities
Ubuntu Security Notices· 52
Ubuntu patched curl flaws that may bypass LDAP peer checks or allow HTTP/2 crashes and code execution.
- · 1d agoUSN-8487-2: curl regression
Ubuntu Security Notices· 42
Ubuntu patches an incomplete curl fix for CVE-2026-8927 and related connection-reuse flaws.
Vulnerabilities in this storyAll →
- CVE-2026-189249.1<1%Use-After-Free in libcurl HTTP/2 Server Push Handling with Shared Connectionspublished · curl project (curl.se) libcurl PoC +1 related