public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
* [rpms/curl] f44: Resolves: CVE-2026-9080 - UAF after pause in socket callback
@ 2026-08-24 14:03 Jan Macku
  0 siblings, 0 replies; only message in thread
From: Jan Macku @ 2026-08-24 14:03 UTC (permalink / raw)
  To: git-commits

A new commit has been pushed.

Repo   : rpms/curl
Branch : f44
Commit : 2f242f26cf3eca5f27ec77c38908a5bafab03cd6
Author : Jan Macku <jamacku@redhat.com>
Date   : 2026-08-24T14:46:04+02:00
Stats  : +103/-0 in 2 file(s)
URL    : https://src.fedoraproject.org/rpms/curl/c/2f242f26cf3eca5f27ec77c38908a5bafab03cd6?branch=f44

Log:
Resolves: CVE-2026-9080 - UAF after pause in socket callback

---
diff --git a/0021-curl-8.18.0-CVE-2026-9080.patch b/0021-curl-8.18.0-CVE-2026-9080.patch
new file mode 100644
index 0000000..08d1286
--- /dev/null
+++ b/0021-curl-8.18.0-CVE-2026-9080.patch
@@ -0,0 +1,96 @@
+From b443308bfaebea79d7355f2edf50df2a903c3dc8 Mon Sep 17 00:00:00 2001
+From: Daniel Stenberg <daniel@haxx.se>
+Date: Tue, 26 May 2026 09:52:19 +0200
+Subject: [PATCH] multi: handle pause in multi socket callback
+
+The mev_sh_entry object might be removed if curl_easy_pause() is called
+from within the socket callback.
+
+Introduced a 'magic' struct field to to 'mev_sh_entry' to make it easier
+to programmatically detect/assert if the pointer is bad - in debug
+builds.
+
+Reported-by: Joshua Rogers
+Closes #21748
+
+(cherry picked from commit 5ab34cba42e4ee4282fe8bab43f311d51b9bf9bd)
+---
+ lib/multi_ev.c | 23 ++++++++++++++++++++---
+ 1 file changed, 20 insertions(+), 3 deletions(-)
+
+diff --git a/lib/multi_ev.c b/lib/multi_ev.c
+index 0c89721f35..e0566e9ff5 100644
+--- a/lib/multi_ev.c
++++ b/lib/multi_ev.c
+@@ -40,6 +40,8 @@ static void mev_in_callback(struct Curl_multi *multi, bool value)
+   multi->in_callback = value;
+ }
+ 
++#define SH_ENTRY_MAGIC 0x570091d
++
+ /* Information about a socket for which we inform the libcurl application
+  * what to supervise (CURL_POLL_IN/CURL_POLL_OUT/CURL_POLL_REMOVE)
+  */
+@@ -51,6 +53,9 @@ struct mev_sh_entry {
+                          * libcurl application to watch out for */
+   unsigned int readers; /* this many transfers want to read */
+   unsigned int writers; /* this many transfers want to write */
++#ifdef DEBUGBUILD
++  unsigned int magic;
++#endif
+   BIT(announced);       /* this socket has been passed to the socket
+                            callback at least once */
+ };
+@@ -75,6 +80,9 @@ static void mev_sh_entry_dtor(void *freethis)
+ {
+   struct mev_sh_entry *entry = (struct mev_sh_entry *)freethis;
+   Curl_uint32_spbset_destroy(&entry->xfers);
++#ifdef DEBUGBUILD
++  entry->magic = 0;
++#endif
+   curlx_free(entry);
+ }
+ 
+@@ -113,7 +121,9 @@ static struct mev_sh_entry *mev_sh_entry_add(struct Curl_hash *sh,
+     mev_sh_entry_dtor(check);
+     return NULL; /* major failure */
+   }
+-
++#ifdef DEBUGBUILD
++  check->magic = SH_ENTRY_MAGIC;
++#endif
+   return check; /* things are good in sockhash land */
+ }
+ 
+@@ -222,6 +232,7 @@ static CURLMcode mev_sh_entry_update(struct Curl_multi *multi,
+ 
+   /* we should only be called when the callback exists */
+   DEBUGASSERT(multi->socket_cb);
++  DEBUGASSERT(entry->magic == SH_ENTRY_MAGIC);
+   if(!multi->socket_cb)
+     return CURLM_OK;
+ 
+@@ -271,12 +282,18 @@ static CURLMcode mev_sh_entry_update(struct Curl_multi *multi,
+   rc = multi->socket_cb(data, s, comboaction, multi->socket_userp,
+                         entry->user_data);
+   mev_in_callback(multi, FALSE);
+-  entry->announced = TRUE;
+   if(rc == -1) {
+     multi->dead = TRUE;
+     return CURLM_ABORTED_BY_CALLBACK;
+   }
+-  entry->action = (unsigned int)comboaction;
++  /* curl_easy_pause() is documented as callable from any callback; it
++   * re-enters mev_assess() which may free this 'entry'. Re-fetch. */
++  entry = mev_sh_entry_get(&multi->ev.sh_entries, s);
++  if(entry) {
++    DEBUGASSERT(entry->magic == SH_ENTRY_MAGIC);
++    entry->announced = TRUE;
++    entry->action = (unsigned int)comboaction;
++  }
+   return CURLM_OK;
+ }
+ 
+-- 
+2.55.0
+

diff --git a/curl.spec b/curl.spec
index 8ecf03b..2dff466 100644
--- a/curl.spec
+++ b/curl.spec
@@ -84,6 +84,9 @@ Patch019: 0019-curl-8.18.0-CVE-2026-9546.patch
 # Fix exposing HTTP/3 early data (CVE-2026-9545)
 Patch020: 0020-curl-8.18.0-CVE-2026-9545.patch
 
+# Fix UAF after pause in socket callback (CVE-2026-9080)
+Patch021: 0021-curl-8.18.0-CVE-2026-9080.patch
+
 # patch making libcurl multilib ready
 Patch101: 0101-curl-7.32.0-multilib.patch
 
@@ -305,6 +308,9 @@ be installed.
 # <https://github.com/bagder/curl/commit/21e82bd6#commitcomment-12226582>
 printf "1801\n" >>tests/data/DISABLED
 
+# disable test 1701 -- nghttpx rejects h2c upgrade with 400 Bad Request
+printf "1701\n" >>tests/data/DISABLED
+
 # test3026: avoid pthread_create() failure due to resource exhaustion on i386
 %ifarch %{ix86}
 sed -e 's|NUM_THREADS 1000$|NUM_THREADS 256|' \
@@ -516,6 +522,7 @@ rm -f ${RPM_BUILD_ROOT}%{_mandir}/man1/wcurl.1*
 - Fix env-set cross-proxy Digest auth state leak (CVE-2026-8927)
 - Fix sending old referer (CVE-2026-9546)
 - Fix exposing HTTP/3 early data (CVE-2026-9545)
+- Fix UAF after pause in socket callback (CVE-2026-9080)
 
 * Wed Jul 29 2026 Jan Macku <jamacku@redhat.com> - 8.18.0-8
 - Fix trailing dot domain super cookie (CVE-2026-8924)

^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-24 14:03 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-24 14:03 [rpms/curl] f44: Resolves: CVE-2026-9080 - UAF after pause in socket callback Jan Macku

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox