Double-free in the GSASL auth context cleanup (SASL over IMAP/POP3/SMTP).
The vulnerable second cleanup path was introduced in curl 8.15.0 by commit
ab650379 (vauth: move auth structs to conn meta data with auto cleanup).
Trixie ships 8.14.1, which predates it, so the double-free cannot occur.
Debian marks this not-affected (vulnerable code not present); affected
range is 8.15.0-8.20.0.