public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
From: Jan Macku <jamacku@redhat.com>
To: git-commits@fedoraproject.org
Subject: [rpms/curl] f44: Resolves: CVE-2026-12064 - proto-default skips SSH verification
Date: Mon, 24 Aug 2026 14:03:14 GMT [thread overview]
Message-ID: <178758019471.1.1956122564688676225.rpms-curl-ebfb55b229ed@fedoraproject.org> (raw)
A new commit has been pushed.
Repo : rpms/curl
Branch : f44
Commit : ebfb55b229ed1f8bb0fb55161adafc45bc2efcb8
Author : Jan Macku <jamacku@redhat.com>
Date : 2026-08-24T12:54:39+02:00
Stats : +262/-0 in 2 file(s)
URL : https://src.fedoraproject.org/rpms/curl/c/ebfb55b229ed1f8bb0fb55161adafc45bc2efcb8?branch=f44
Log:
Resolves: CVE-2026-12064 - proto-default skips SSH verification
---
diff --git a/0015-curl-8.18.0-CVE-2026-12064.patch b/0015-curl-8.18.0-CVE-2026-12064.patch
new file mode 100644
index 0000000..8c349c9
--- /dev/null
+++ b/0015-curl-8.18.0-CVE-2026-12064.patch
@@ -0,0 +1,258 @@
+From bbb2fed4fb5b8526a07607cc5899cdf4f0e16efd Mon Sep 17 00:00:00 2001
+From: Daniel Stenberg <daniel@haxx.se>
+Date: Fri, 12 Jun 2026 09:01:22 +0200
+Subject: [PATCH] config2setopts: use default protocol properly
+
+Verified by test 1724, 1725 and 2036
+
+Closes #21983
+
+(cherry picked from commit ab3bb8cd8be8f9d4acb97da0418abc279182041e)
+---
+ docs/cmdline-opts/proto-default.md | 6 +++-
+ src/config2setopts.c | 51 +++++++++++++++++-----------
+ tests/data/Makefile.am | 3 +-
+ tests/data/test1724 | 53 ++++++++++++++++++++++++++++++
+ tests/data/test1725 | 29 ++++++++++++++++
+ tests/data/test2036 | 26 +++++++++++++++
+ 6 files changed, 146 insertions(+), 22 deletions(-)
+ create mode 100644 tests/data/test1724
+ create mode 100644 tests/data/test1725
+ create mode 100644 tests/data/test2036
+
+diff --git a/docs/cmdline-opts/proto-default.md b/docs/cmdline-opts/proto-default.md
+index 209e5cdc83..903fac73a5 100644
+--- a/docs/cmdline-opts/proto-default.md
++++ b/docs/cmdline-opts/proto-default.md
+@@ -16,7 +16,8 @@ Example:
+
+ # `--proto-default`
+
+-Use *protocol* for any provided URL missing a scheme.
++Use *protocol* for any provided URL missing a scheme. The case-insensitive
++name should be given without any `://` suffix.
+
+ An unknown or unsupported protocol causes error *CURLE_UNSUPPORTED_PROTOCOL*.
+
+@@ -24,3 +25,6 @@ This option does not change the default proxy protocol (http).
+
+ Without this option set, curl guesses protocol based on the hostname, see
+ --url for details.
++
++The default protocol cannot be set to `ipfs` or `ipns`. Those schemes need to
++be used explicitly in the URL.
+diff --git a/src/config2setopts.c b/src/config2setopts.c
+index d462e8cd54..a69f3adb20 100644
+--- a/src/config2setopts.c
++++ b/src/config2setopts.c
+@@ -143,29 +143,40 @@ static CURLcode url_proto_and_rewrite(char **url,
+ curl_url_set(uh, CURLUPART_URL, *url,
+ CURLU_GUESS_SCHEME | CURLU_NON_SUPPORT_SCHEME);
+ if(!uc) {
+- uc = curl_url_get(uh, CURLUPART_SCHEME, &schemep, CURLU_DEFAULT_SCHEME);
+- if(!uc) {
+-#ifdef CURL_DISABLE_IPFS
+- (void)config;
+-#else
+- if(curl_strequal(schemep, proto_ipfs) ||
+- curl_strequal(schemep, proto_ipns)) {
+- result = ipfs_url_rewrite(uh, schemep, url, config);
+- /* short-circuit proto_token, we know it is ipfs or ipns */
+- if(curl_strequal(schemep, proto_ipfs))
+- proto = proto_ipfs;
+- else if(curl_strequal(schemep, proto_ipns))
+- proto = proto_ipns;
+- if(result)
+- config->synthetic_error = TRUE;
++ if(config->proto_default) {
++ /* when a default proto is requested, do not guess */
++ uc = curl_url_get(uh, CURLUPART_SCHEME, &schemep,
++ CURLU_NO_GUESS_SCHEME);
++ if(uc == CURLUE_NO_SCHEME) {
++ /* use the default */
++ proto = proto_token(config->proto_default);
++ if(proto)
++ uc = CURLUE_OK;
+ }
+- else
+-#endif /* !CURL_DISABLE_IPFS */
+- proto = proto_token(schemep);
+- curl_free(schemep);
+ }
+- else if(uc == CURLUE_OUT_OF_MEMORY)
++ else {
++ uc = curl_url_get(uh, CURLUPART_SCHEME, &schemep,
++ CURLU_DEFAULT_SCHEME);
++ }
++ if(schemep)
++ proto = proto_token(schemep);
++#ifndef CURL_DISABLE_IPFS
++ if(!uc &&
++ (curl_strequal(schemep, proto_ipfs) ||
++ curl_strequal(schemep, proto_ipns))) {
++ result = ipfs_url_rewrite(uh, schemep, url, config);
++ /* short-circuit proto_token, we know it is ipfs or ipns */
++ if(curl_strequal(schemep, proto_ipfs))
++ proto = proto_ipfs;
++ else if(curl_strequal(schemep, proto_ipns))
++ proto = proto_ipns;
++ if(result)
++ config->synthetic_error = TRUE;
++ }
++#endif /* !CURL_DISABLE_IPFS */
++ if(uc == CURLUE_OUT_OF_MEMORY)
+ result = CURLE_OUT_OF_MEMORY;
++ curl_free(schemep);
+ }
+ else if(uc == CURLUE_OUT_OF_MEMORY)
+ result = CURLE_OUT_OF_MEMORY;
+diff --git a/tests/data/Makefile.am b/tests/data/Makefile.am
+index b050f708eb..57e7508751 100644
+--- a/tests/data/Makefile.am
++++ b/tests/data/Makefile.am
+@@ -230,6 +230,7 @@ test1680 test1681 test1682 test1683 test1686 \
+ \
+ test1700 test1701 test1702 test1703 test1704 test1705 test1706 test1707 \
+ test1708 test1709 test1710 test1711 \
++test1724 test1725 \
+ \
+ test1800 test1801 test1802 test1850 \
+ \
+@@ -247,7 +248,7 @@ test2000 test2001 test2002 test2003 test2004 test2005 test2006 \
+ \
+ test2023 \
+ test2024 test2025 test2026 test2027 test2028 test2029 test2030 test2031 \
+-test2032 test2033 test2034 test2035 test2037 test2038 test2039 \
++test2032 test2033 test2034 test2035 test2036 test2037 test2038 test2039 \
+ test2040 test2041 test2042 test2043 test2044 test2045 test2046 test2047 \
+ test2048 test2049 test2050 test2051 test2052 test2053 test2054 test2055 \
+ test2056 test2057 test2058 test2059 test2060 test2061 test2062 test2063 \
+diff --git a/tests/data/test1724 b/tests/data/test1724
+new file mode 100644
+index 0000000000..3cd328e39c
+--- /dev/null
++++ b/tests/data/test1724
+@@ -0,0 +1,53 @@
++<?xml version="1.0" encoding="US-ASCII"?>
++<testcase>
++<info>
++<keywords>
++IPFS
++</keywords>
++</info>
++
++# Server-side
++<reply>
++<data nocheck="yes">
++HTTP/1.1 200 OK
++Date: Tue, 09 Nov 2010 14:49:00 GMT
++Server: test-server/fake
++Last-Modified: Tue, 13 Jun 2000 12:10:00 GMT
++ETag: "21025-dc7-39462498"
++Accept-Ranges: bytes
++Content-Length: 21
++Connection: close
++Content-Type: text/plain
++Funny-head: yesyes
++
++Hello curl from IPFS
++</data>
++</reply>
++
++# Client-side
++<client>
++<features>
++ipfs
++</features>
++<server>
++http
++</server>
++<name>
++IPFS with --proto-default HTTP
++</name>
++<command>
++--ipfs-gateway http://%HOSTIP:%HTTPPORT ipfs://bafybeidecnvkrygux6uoukouzps5ofkeevoqland7kopseiod6pzqvjg7u --proto-default http
++</command>
++</client>
++
++# Verify data after the test has been "shot"
++<verify>
++<protocol crlf="headers">
++GET /ipfs/bafybeidecnvkrygux6uoukouzps5ofkeevoqland7kopseiod6pzqvjg7u HTTP/1.1
++Host: %HOSTIP:%HTTPPORT
++User-Agent: curl/%VERSION
++Accept: */*
++
++</protocol>
++</verify>
++</testcase>
+diff --git a/tests/data/test1725 b/tests/data/test1725
+new file mode 100644
+index 0000000000..2a882c791d
+--- /dev/null
++++ b/tests/data/test1725
+@@ -0,0 +1,29 @@
++<?xml version="1.0" encoding="US-ASCII"?>
++<testcase>
++<info>
++<keywords>
++SCP
++server key check
++</keywords>
++</info>
++
++# Client-side
++<client>
++<server>
++scp
++</server>
++<name>
++SCP incorrect host key with --proto-default SCP
++</name>
++<command>
++--hostpubmd5 00000000000000000000000000000000 --key %LOGDIR/server/curl_client_key --pubkey %LOGDIR/server/curl_client_key.pub -u %USER: %HOSTIP:%SSHPORT%SCP_PWD/%LOGDIR/irrelevant-file --insecure --proto-default SCP
++</command>
++</client>
++
++# Verify data after the test has been "shot"
++<verify>
++<errorcode>
++60
++</errorcode>
++</verify>
++</testcase>
+diff --git a/tests/data/test2036 b/tests/data/test2036
+new file mode 100644
+index 0000000000..b017a71abc
+--- /dev/null
++++ b/tests/data/test2036
+@@ -0,0 +1,26 @@
++<?xml version="1.0" encoding="US-ASCII"?>
++<testcase>
++<info>
++<keywords>
++--proto-default
++</keywords>
++</info>
++
++# Client-side
++<client>
++<name>
++Attempt to set a default protocol with :// suffix
++</name>
++<command>
++--proto-default https://
++</command>
++</client>
++
++# Verify data after the test has been "shot"
++<verify>
++# CURLE_UNSUPPORTED_PROTOCOL is error code 1
++<errorcode>
++1
++</errorcode>
++</verify>
++</testcase>
+--
+2.55.0
+
diff --git a/curl.spec b/curl.spec
index 677f71d..94dc738 100644
--- a/curl.spec
+++ b/curl.spec
@@ -66,6 +66,9 @@ Patch013: 0013-curl-8.18.0-CVE-2026-11352.patch
# Fix WS Auto-PONG memory exhaustion (CVE-2026-11586)
Patch014: 0014-curl-8.18.0-CVE-2026-11586.patch
+# Fix proto-default skips SSH verification (CVE-2026-12064)
+Patch015: 0015-curl-8.18.0-CVE-2026-12064.patch
+
# patch making libcurl multilib ready
Patch101: 0101-curl-7.32.0-multilib.patch
@@ -492,6 +495,7 @@ rm -f ${RPM_BUILD_ROOT}%{_mandir}/man1/wcurl.1*
* Mon Aug 24 2026 Jan Macku <jamacku@redhat.com> - 8.18.0-9
- Fix QUIC zero-length UDP datagrams busy-loop (CVE-2026-11352)
- Fix WS Auto-PONG memory exhaustion (CVE-2026-11586)
+- Fix proto-default skips SSH verification (CVE-2026-12064)
* Wed Jul 29 2026 Jan Macku <jamacku@redhat.com> - 8.18.0-8
- Fix trailing dot domain super cookie (CVE-2026-8924)
reply other threads:[~2026-08-24 14:03 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=178758019471.1.1956122564688676225.rpms-curl-ebfb55b229ed@fedoraproject.org \
--to=jamacku@redhat.com \
--cc=git-commits@fedoraproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox