public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
From: Jan Macku <jamacku@redhat.com>
To: git-commits@fedoraproject.org
Subject: [rpms/curl] f43: Resolves: CVE-2026-9545 - exposing HTTP/3 early data
Date: Thu, 27 Aug 2026 15:01:16 GMT [thread overview]
Message-ID: <178784287619.1.11268742266415808151.rpms-curl-83347b000d38@fedoraproject.org> (raw)
A new commit has been pushed.
Repo : rpms/curl
Branch : f43
Commit : 83347b000d38a5f7883ece673c0a3fca6da347d8
Author : Jan Macku <jamacku@redhat.com>
Date : 2026-08-26T19:44:11+02:00
Stats : +76/-0 in 2 file(s)
URL : https://src.fedoraproject.org/rpms/curl/c/83347b000d38a5f7883ece673c0a3fca6da347d8?branch=f43
Log:
Resolves: CVE-2026-9545 - exposing HTTP/3 early data
---
diff --git a/0017-curl-8.15.0-CVE-2026-9545.patch b/0017-curl-8.15.0-CVE-2026-9545.patch
new file mode 100644
index 0000000..8df629f
--- /dev/null
+++ b/0017-curl-8.15.0-CVE-2026-9545.patch
@@ -0,0 +1,72 @@
+From b8c9fd97c1786c2cd47faa2d3b646c134f41db54 Mon Sep 17 00:00:00 2001
+From: Stefan Eissing <stefan@eissing.org>
+Date: Thu, 21 May 2026 14:21:59 +0200
+Subject: [PATCH] ngtcp2: fail handshake directly
+
+When certificate verification fails, error out of the handshake
+callback, forcing ngtcp2 to stop processing the connection any further.
+
+Closes #21712
+
+(cherry picked from commit 7b9613fa9b1a5e04301a3920eef58e8138dad05e)
+---
+ lib/vquic/curl_ngtcp2.c | 14 +++++++++++---
+ 1 file changed, 11 insertions(+), 3 deletions(-)
+
+diff --git a/lib/vquic/curl_ngtcp2.c b/lib/vquic/curl_ngtcp2.c
+index 69d54ecce2..24fe7ec0b0 100644
+--- a/lib/vquic/curl_ngtcp2.c
++++ b/lib/vquic/curl_ngtcp2.c
+@@ -463,7 +463,7 @@ static int cf_ngtcp2_handshake_completed(ngtcp2_conn *tconn, void *user_data)
+ data = CF_DATA_CURRENT(cf);
+ DEBUGASSERT(data);
+ if(!ctx || !data)
+- return NGHTTP3_ERR_CALLBACK_FAILURE;
++ return NGTCP2_ERR_CALLBACK_FAILURE;
+
+ ctx->handshake_at = curlx_now();
+ ctx->tls_handshake_complete = TRUE;
+@@ -472,6 +472,9 @@ static int cf_ngtcp2_handshake_completed(ngtcp2_conn *tconn, void *user_data)
+
+ ctx->tls_vrfy_result = Curl_vquic_tls_verify_peer(&ctx->tls, cf,
+ data, &ctx->peer);
++ if(ctx->tls_vrfy_result)
++ return NGTCP2_ERR_CALLBACK_FAILURE;
++
+ CURL_TRC_CF(data, cf, "handshake complete after %dms",
+ (int)curlx_timediff(ctx->handshake_at, ctx->started_at));
+ /* In case of earlydata, where we simulate being connected, update
+@@ -1329,9 +1332,10 @@ static CURLcode cf_ngtcp2_recv(struct Curl_cfilter *cf, struct Curl_easy *data,
+ out:
+ result = Curl_1st_err(result, cf_progress_egress(cf, data, &pktx));
+ result = Curl_1st_err(result, check_and_set_expiry(cf, data, &pktx));
++ if(ctx->tls_vrfy_result)
++ result = ctx->tls_vrfy_result;
+
+- CURL_TRC_CF(data, cf, "[%" FMT_PRId64 "] cf_recv(blen=%zu) -> %dm, %zu",
+-
++ CURL_TRC_CF(data, cf, "[%" FMT_PRId64 "] cf_recv(blen=%zu) -> %d, %zu",
+ stream ? stream->id : -1, blen, result, *pnread);
+ CF_DATA_RESTORE(cf, save);
+ return result;
+@@ -1657,6 +1661,8 @@ static CURLcode cf_ngtcp2_send(struct Curl_cfilter *cf, struct Curl_easy *data,
+
+ out:
+ result = Curl_1st_err(result, check_and_set_expiry(cf, data, &pktx));
++ if(ctx->tls_vrfy_result)
++ result = ctx->tls_vrfy_result;
+
+ CURL_TRC_CF(data, cf, "[%" FMT_PRId64 "] cf_send(len=%zu) -> %d, %zu",
+ stream ? stream->id : -1, len, result, *pnwritten);
+@@ -2565,6 +2571,8 @@ static CURLcode cf_ngtcp2_connect(struct Curl_cfilter *cf,
+ }
+
+ out:
++ if(ctx->tls_vrfy_result)
++ result = ctx->tls_vrfy_result;
+ if(result == CURLE_RECV_ERROR && ctx->qconn &&
+ ngtcp2_conn_in_draining_period(ctx->qconn)) {
+ /* When a QUIC server instance is shutting down, it may send us a
+--
+2.55.0
+
diff --git a/curl.spec b/curl.spec
index eeb9c43..ee6fdd9 100644
--- a/curl.spec
+++ b/curl.spec
@@ -64,6 +64,9 @@ Patch015: 0015-curl-8.15.0-CVE-2026-8925.patch
# fix env-set cross-proxy Digest auth state leak (CVE-2026-8927)
Patch016: 0016-curl-8.15.0-CVE-2026-8927.patch
+# fix exposing HTTP/3 early data (CVE-2026-9545)
+Patch017: 0017-curl-8.15.0-CVE-2026-9545.patch
+
# patch making libcurl multilib ready
Patch101: 0101-curl-7.32.0-multilib.patch
@@ -468,6 +471,7 @@ rm -f ${RPM_BUILD_ROOT}%{_mandir}/man1/wcurl.1*
- fix wrong STARTTLS connection reuse (CVE-2026-8286)
- fix SASL double-free (CVE-2026-8925)
- fix env-set cross-proxy Digest auth state leak (CVE-2026-8927)
+- fix exposing HTTP/3 early data (CVE-2026-9545)
* Mon Aug 03 2026 Jan Macku <jamacku@redhat.com> - 8.15.0-8
- fix cross-proxy Digest auth state leak (CVE-2026-7168)
reply other threads:[~2026-08-27 15:01 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=178784287619.1.11268742266415808151.rpms-curl-83347b000d38@fedoraproject.org \
--to=jamacku@redhat.com \
--cc=git-commits@fedoraproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox