public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
From: Jan Macku <jamacku@redhat.com>
To: git-commits@fedoraproject.org
Subject: [rpms/curl] f43: Resolves: CVE-2026-8925 - SASL double-free
Date: Thu, 27 Aug 2026 15:01:15 GMT	[thread overview]
Message-ID: <178784287521.1.16411546163053766735.rpms-curl-36bffe426aea@fedoraproject.org> (raw)

A new commit has been pushed.

Repo   : rpms/curl
Branch : f43
Commit : 36bffe426aea4b71683b1209a04c8481d6ea9e47
Author : Jan Macku <jamacku@redhat.com>
Date   : 2026-08-26T16:13:09+02:00
Stats  : +62/-0 in 2 file(s)
URL    : https://src.fedoraproject.org/rpms/curl/c/36bffe426aea4b71683b1209a04c8481d6ea9e47?branch=f43

Log:
Resolves: CVE-2026-8925 - SASL double-free

---
diff --git a/0015-curl-8.15.0-CVE-2026-8925.patch b/0015-curl-8.15.0-CVE-2026-8925.patch
new file mode 100644
index 0000000..e79b4f4
--- /dev/null
+++ b/0015-curl-8.15.0-CVE-2026-8925.patch
@@ -0,0 +1,58 @@
+From 56a1fac81fa0d438f04ba114a5beae65a26d66b4 Mon Sep 17 00:00:00 2001
+From: Viktor Szakats <commit@vsz.me>
+Date: Thu, 14 May 2026 14:35:21 +0200
+Subject: [PATCH] gsasl: fix potential double free
+
+Also:
+- require libgsasl 1.6.0+ (2010-12-14) for a `gsasl_finish()` that
+  handles a NULL argument.
+  Ref: https://gitlab.com/gsasl/gsasl/-/commit/b550032df8488a9ceaa3cfd4c634947d8f219717
+
+Reported-by: Joshua Rogers (Aisle Research)
+
+Closes #21609
+
+(cherry picked from commit 3da249e1f0716c06644ed3522a37a8bf81808012)
+---
+ docs/INTERNALS.md | 1 +
+ lib/vauth/gsasl.c | 5 +++++
+ 2 files changed, 6 insertions(+)
+
+diff --git a/docs/INTERNALS.md b/docs/INTERNALS.md
+index a0b1adc9ed..64f04983e1 100644
+--- a/docs/INTERNALS.md
++++ b/docs/INTERNALS.md
+@@ -32,6 +32,7 @@ versions of libs and build tools.
+  - c-ares       1.6.0
+  - libssh       0.9.0
+  - libidn2      2.0.0
++ - libgsasl     1.6.0
+  - wolfSSL      3.4.6
+  - OpenLDAP     2.0
+  - MIT Kerberos 1.2.4
+diff --git a/lib/vauth/gsasl.c b/lib/vauth/gsasl.c
+index 3684c8f4b2..602160141b 100644
+--- a/lib/vauth/gsasl.c
++++ b/lib/vauth/gsasl.c
+@@ -36,6 +36,10 @@
+ 
+ #include <gsasl.h>
+ 
++#if GSASL_VERSION_NUMBER < 0x010600
++#error "requires libgsasl 1.6.0+"
++#endif
++
+ /* The last 3 #include files should be in this order */
+ #include "../curl_printf.h"
+ #include "../curl_memory.h"
+@@ -56,6 +60,7 @@ bool Curl_auth_gsasl_is_supported(struct Curl_easy *data,
+   res = gsasl_client_start(gsasl->ctx, mech, &gsasl->client);
+   if(res != GSASL_OK) {
+     gsasl_done(gsasl->ctx);
++    gsasl->ctx = NULL;
+     return FALSE;
+   }
+ 
+-- 
+2.55.0
+

diff --git a/curl.spec b/curl.spec
index f74c427..b1714e9 100644
--- a/curl.spec
+++ b/curl.spec
@@ -58,6 +58,9 @@ Patch013: 0013-curl-8.15.0-CVE-2026-12064.patch
 # fix wrong STARTTLS connection reuse (CVE-2026-8286)
 Patch014: 0014-curl-8.15.0-CVE-2026-8286.patch
 
+# fix SASL double-free (CVE-2026-8925)
+Patch015: 0015-curl-8.15.0-CVE-2026-8925.patch
+
 # patch making libcurl multilib ready
 Patch101: 0101-curl-7.32.0-multilib.patch
 
@@ -460,6 +463,7 @@ rm -f ${RPM_BUILD_ROOT}%{_mandir}/man1/wcurl.1*
 * Wed Aug 26 2026 Jan Macku <jamacku@redhat.com> - 8.15.0-9
 - fix proto-default skips SSH verification (CVE-2026-12064)
 - fix wrong STARTTLS connection reuse (CVE-2026-8286)
+- fix SASL double-free (CVE-2026-8925)
 
 * Mon Aug 03 2026 Jan Macku <jamacku@redhat.com> - 8.15.0-8
 - fix cross-proxy Digest auth state leak (CVE-2026-7168)

                 reply	other threads:[~2026-08-27 15:01 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=178784287521.1.16411546163053766735.rpms-curl-36bffe426aea@fedoraproject.org \
    --to=jamacku@redhat.com \
    --cc=git-commits@fedoraproject.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox