cURL is a computer software project providing a library (libcurl) and command-line tool (curl) for transferring data using various protocols.
Security Fix(es):
curl contains an out-of-bounds read vulnerability in cookie path comparison logic. When a secure cookie is set via HTTPS and then the client is redirected to an insecure HTTP site using the same cookie name with path="/", a bug in path comparison logic causes reading beyond heap buffer boundaries. This may result in crashes or incorrectly allowing insecure sites to override secure cookie contents, contrary to security expectations. The attacker needs control of an HTTP site with the same name as the HTTPS version or MITM capability.(CVE-2025-9086)
{
"severity": "High"
}{
"noarch": [
"curl-help-7.71.1-43.oe2003sp4.noarch.rpm"
],
"aarch64": [
"curl-7.71.1-43.oe2003sp4.aarch64.rpm",
"curl-debuginfo-7.71.1-43.oe2003sp4.aarch64.rpm",
"curl-debugsource-7.71.1-43.oe2003sp4.aarch64.rpm",
"libcurl-7.71.1-43.oe2003sp4.aarch64.rpm",
"libcurl-devel-7.71.1-43.oe2003sp4.aarch64.rpm"
],
"x86_64": [
"curl-7.71.1-43.oe2003sp4.x86_64.rpm",
"curl-debuginfo-7.71.1-43.oe2003sp4.x86_64.rpm",
"curl-debugsource-7.71.1-43.oe2003sp4.x86_64.rpm",
"libcurl-7.71.1-43.oe2003sp4.x86_64.rpm",
"libcurl-devel-7.71.1-43.oe2003sp4.x86_64.rpm"
],
"src": [
"curl-7.71.1-43.oe2003sp4.src.rpm"
]
}{
"noarch": [
"curl-help-7.79.1-42.oe2203sp3.noarch.rpm"
],
"aarch64": [
"curl-7.79.1-42.oe2203sp3.aarch64.rpm",
"curl-debuginfo-7.79.1-42.oe2203sp3.aarch64.rpm",
"curl-debugsource-7.79.1-42.oe2203sp3.aarch64.rpm",
"libcurl-7.79.1-42.oe2203sp3.aarch64.rpm",
"libcurl-devel-7.79.1-42.oe2203sp3.aarch64.rpm"
],
"x86_64": [
"curl-7.79.1-42.oe2203sp3.x86_64.rpm",
"curl-debuginfo-7.79.1-42.oe2203sp3.x86_64.rpm",
"curl-debugsource-7.79.1-42.oe2203sp3.x86_64.rpm",
"libcurl-7.79.1-42.oe2203sp3.x86_64.rpm",
"libcurl-devel-7.79.1-42.oe2203sp3.x86_64.rpm"
],
"src": [
"curl-7.79.1-42.oe2203sp3.src.rpm"
]
}{
"noarch": [
"curl-help-7.79.1-42.oe2203sp4.noarch.rpm"
],
"aarch64": [
"curl-7.79.1-42.oe2203sp4.aarch64.rpm",
"curl-debuginfo-7.79.1-42.oe2203sp4.aarch64.rpm",
"curl-debugsource-7.79.1-42.oe2203sp4.aarch64.rpm",
"libcurl-7.79.1-42.oe2203sp4.aarch64.rpm",
"libcurl-devel-7.79.1-42.oe2203sp4.aarch64.rpm"
],
"x86_64": [
"curl-7.79.1-42.oe2203sp4.x86_64.rpm",
"curl-debuginfo-7.79.1-42.oe2203sp4.x86_64.rpm",
"curl-debugsource-7.79.1-42.oe2203sp4.x86_64.rpm",
"libcurl-7.79.1-42.oe2203sp4.x86_64.rpm",
"libcurl-devel-7.79.1-42.oe2203sp4.x86_64.rpm"
],
"src": [
"curl-7.79.1-42.oe2203sp4.src.rpm"
]
}{
"noarch": [
"curl-help-8.4.0-22.oe2403.noarch.rpm",
"curl-help-8.4.0-22.oe2403sp1.noarch.rpm",
"curl-help-8.4.0-22.oe2403sp2.noarch.rpm"
],
"aarch64": [
"curl-8.4.0-22.oe2403.aarch64.rpm",
"curl-debuginfo-8.4.0-22.oe2403.aarch64.rpm",
"curl-debugsource-8.4.0-22.oe2403.aarch64.rpm",
"libcurl-8.4.0-22.oe2403.aarch64.rpm",
"libcurl-devel-8.4.0-22.oe2403.aarch64.rpm",
"curl-8.4.0-22.oe2403sp1.aarch64.rpm",
"curl-debuginfo-8.4.0-22.oe2403sp1.aarch64.rpm",
"curl-debugsource-8.4.0-22.oe2403sp1.aarch64.rpm",
"libcurl-8.4.0-22.oe2403sp1.aarch64.rpm",
"libcurl-devel-8.4.0-22.oe2403sp1.aarch64.rpm",
"curl-8.4.0-22.oe2403sp2.aarch64.rpm",
"curl-debuginfo-8.4.0-22.oe2403sp2.aarch64.rpm",
"curl-debugsource-8.4.0-22.oe2403sp2.aarch64.rpm",
"libcurl-8.4.0-22.oe2403sp2.aarch64.rpm",
"libcurl-devel-8.4.0-22.oe2403sp2.aarch64.rpm"
],
"x86_64": [
"curl-8.4.0-22.oe2403.x86_64.rpm",
"curl-debuginfo-8.4.0-22.oe2403.x86_64.rpm",
"curl-debugsource-8.4.0-22.oe2403.x86_64.rpm",
"libcurl-8.4.0-22.oe2403.x86_64.rpm",
"libcurl-devel-8.4.0-22.oe2403.x86_64.rpm",
"curl-8.4.0-22.oe2403sp1.x86_64.rpm",
"curl-debuginfo-8.4.0-22.oe2403sp1.x86_64.rpm",
"curl-debugsource-8.4.0-22.oe2403sp1.x86_64.rpm",
"libcurl-8.4.0-22.oe2403sp1.x86_64.rpm",
"libcurl-devel-8.4.0-22.oe2403sp1.x86_64.rpm",
"curl-8.4.0-22.oe2403sp2.x86_64.rpm",
"curl-debuginfo-8.4.0-22.oe2403sp2.x86_64.rpm",
"curl-debugsource-8.4.0-22.oe2403sp2.x86_64.rpm",
"libcurl-8.4.0-22.oe2403sp2.x86_64.rpm",
"libcurl-devel-8.4.0-22.oe2403sp2.x86_64.rpm"
],
"src": [
"curl-8.4.0-22.oe2403.src.rpm",
"curl-8.4.0-22.oe2403sp1.src.rpm",
"curl-8.4.0-22.oe2403sp2.src.rpm"
]
}{
"noarch": [
"curl-help-8.4.0-22.oe2403sp1.noarch.rpm"
],
"aarch64": [
"curl-8.4.0-22.oe2403sp1.aarch64.rpm",
"curl-debuginfo-8.4.0-22.oe2403sp1.aarch64.rpm",
"curl-debugsource-8.4.0-22.oe2403sp1.aarch64.rpm",
"libcurl-8.4.0-22.oe2403sp1.aarch64.rpm",
"libcurl-devel-8.4.0-22.oe2403sp1.aarch64.rpm"
],
"x86_64": [
"curl-8.4.0-22.oe2403sp1.x86_64.rpm",
"curl-debuginfo-8.4.0-22.oe2403sp1.x86_64.rpm",
"curl-debugsource-8.4.0-22.oe2403sp1.x86_64.rpm",
"libcurl-8.4.0-22.oe2403sp1.x86_64.rpm",
"libcurl-devel-8.4.0-22.oe2403sp1.x86_64.rpm"
],
"src": [
"curl-8.4.0-22.oe2403sp1.src.rpm"
]
}{
"noarch": [
"curl-help-8.4.0-22.oe2403sp2.noarch.rpm"
],
"aarch64": [
"curl-8.4.0-22.oe2403sp2.aarch64.rpm",
"curl-debuginfo-8.4.0-22.oe2403sp2.aarch64.rpm",
"curl-debugsource-8.4.0-22.oe2403sp2.aarch64.rpm",
"libcurl-8.4.0-22.oe2403sp2.aarch64.rpm",
"libcurl-devel-8.4.0-22.oe2403sp2.aarch64.rpm"
],
"x86_64": [
"curl-8.4.0-22.oe2403sp2.x86_64.rpm",
"curl-debuginfo-8.4.0-22.oe2403sp2.x86_64.rpm",
"curl-debugsource-8.4.0-22.oe2403sp2.x86_64.rpm",
"libcurl-8.4.0-22.oe2403sp2.x86_64.rpm",
"libcurl-devel-8.4.0-22.oe2403sp2.x86_64.rpm"
],
"src": [
"curl-8.4.0-22.oe2403sp2.src.rpm"
]
}