Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1269285 > unrolled thread

Bug#1120262: trixie-pu: package curl/8.14.1-2+deb13u1

Started byAlex <alex@puer-robustus.eu>
First post2025-11-06 14:40 +0100
Last post2025-11-09 17:20 +0100
Articles 6 — 5 participants

Back to article view | Back to linux.debian.bugs.dist


Contents

  Bug#1120262: trixie-pu: package curl/8.14.1-2+deb13u1 Alex <alex@puer-robustus.eu> - 2025-11-06 14:40 +0100
    Bug#1120262: trixie-pu: package curl/8.14.1-2+deb13u1 "Adam D. Barratt" <adam@adam-barratt.org.uk> - 2025-11-06 20:20 +0100
    Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance Adam D Barratt <adam@adam-barratt.org.uk> - 2025-11-07 20:40 +0100
      Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance Paul Gevers <elbrus@debian.org> - 2025-11-09 12:00 +0100
        Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance Adrian Bunk <bunk@debian.org> - 2025-11-09 14:20 +0100
          Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance Paul Gevers <elbrus@debian.org> - 2025-11-09 17:20 +0100

#1269285 — Bug#1120262: trixie-pu: package curl/8.14.1-2+deb13u1

FromAlex <alex@puer-robustus.eu>
Date2025-11-06 14:40 +0100
SubjectBug#1120262: trixie-pu: package curl/8.14.1-2+deb13u1
Message-ID<LO8nv-aVFX-3@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Package: release.debian.org
Severity: normal
Tags: trixie
X-Debbugs-Cc: curl@packages.debian.org
Control: affects -1 + src:curl
User: release.debian.org@packages.debian.org
Usertags: pu

[ Reason ]

The curl package version in Debian Trixie suffers from three minor CVEs:

[1]: https://security-tracker.debian.org/tracker/CVE-2025-9086
[2]: https://security-tracker.debian.org/tracker/CVE-2025-10148
[3]: https://security-tracker.debian.org/tracker/CVE-2025-11563

The updated package version contains the backported upstream patches to
close those vulnerabilities and also two bug fixes for wcurl: a man page fix
and a fix to allow overriding the output file name with --curl-options.

[ Impact ]

If the update is not approved, all curl installations on Debian Trixie
machines will remain vulnerable to the exploits:

- CVE-2025-9086 allows for an out-of-bound read for cookie path
- A fixed mask pattern discovered in CVE-2025-10148 allows a malicious
  server to induce traffic between the two communicating parties that
  could be interpreted by an involved proxy (configured or transparent)
  as genuine, real, HTTP traffic with content and thereby poison its
  cache. That cached poisoned content could then be served to all users
  of that proxy.
- CVE-2025-11563 is a path traversal vulnerability where users might end up
  with the downloaded files placed in a folder outside of the current working
  directory unintentionally.

Regarding the additional wcurl fixes:
- The manpage fix is for an example invocation where the user wants downloads
  to be resumed, it's an important use case and was reported by a user.
- The fix for overriding the output filename with --curl-options is not that
  important, given users will use --output directly, but the fix is extremely
  straightforward.

[ Tests ]

All upstream tests run successfully.
Samuel Henrique <samueloph> has also run the reproducer for CVE-2025-9086
manually and confirmed that the patch fixes the issue.

[ Risks ]

Errors in backporting the patches which either don't close the
vulnerabilities or introduce regressions which are not caught by the
upstream tests.

The cookie handling patch with the fix for CVE-2025-9086 could be
carried over as is from upstream:
https://salsa.debian.org/debian/curl/-/commit/700cf2ca7aa6b461c37f28f4f2634850dbf3b971

The websocket patch for CVE-2025-10148 required some backporting to make
the expected return types match:
https://salsa.debian.org/debian/curl/-/commit/98f245da1dee1f4c549cd3b826a8bcc49cb03d71

The wcurl patches only required minimal backporting changes:
https://salsa.debian.org/debian/curl/-/commit/a50e1fa30dd7a58af13d4ce029352520b4e20dd1
https://salsa.debian.org/debian/curl/-/commit/84b76ed84665be069b70b14b0a857a6440708d9b
https://salsa.debian.org/debian/curl/-/commit/84e8794b04007dbc07db29ea3b3ab66873339986

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

[ Changes ]

* Backported patch to not drop leading slash in cookie path if that is
  its only component.
* Backported patch which ensures the use of a new, random mask for each
  outgoing frame on websockets.
* Backported wcurl patches for the CVE, manpage fix, and output filename
  overriding fix.
* salsa-ci.yml: Disable arm builds, they are currently broken.

[ Other info ]
Nothing that I am aware of.

[toc] | [next] | [standalone]


#1269325

From"Adam D. Barratt" <adam@adam-barratt.org.uk>
Date2025-11-06 20:20 +0100
Message-ID<LOdGx-aZdX-1@gated-at.bofh.it>
In reply to#1269285
Control: tags -1 + confirmed

On Thu, 2025-11-06 at 14:30 +0100, Alex wrote:
> The curl package version in Debian Trixie suffers from three minor
> CVEs:
> 
> [1]: https://security-tracker.debian.org/tracker/CVE-2025-9086
> [2]: https://security-tracker.debian.org/tracker/CVE-2025-10148
> [3]: https://security-tracker.debian.org/tracker/CVE-2025-11563
> 
> The updated package version contains the backported upstream patches
> to close those vulnerabilities and also two bug fixes for wcurl: a
> man page fix and a fix to allow overriding the output file name with
> --curl-options.

Please go ahead.

Regards,

Adam

[toc] | [prev] | [next] | [standalone]


#1269453 — Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance

FromAdam D Barratt <adam@adam-barratt.org.uk>
Date2025-11-07 20:40 +0100
SubjectBug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance
Message-ID<LOAtr-beIs-7@gated-at.bofh.it>
In reply to#1269285
package release.debian.org
tags 1120262 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: curl
Version: 8.14.1-2+deb13u1

Explanation: fix buffer over-read issue [CVE-2025-9086]; fix cache poisoning issue [CVE-2025-10148]; fix path traversal issue [CVE-2025-10148]; allow --output to be overridden by --curl-options; fix manpage example for "continue-at"

[toc] | [prev] | [next] | [standalone]


#1269629 — Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance

FromPaul Gevers <elbrus@debian.org>
Date2025-11-09 12:00 +0100
SubjectBug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance
Message-ID<LPbjj-bDsB-1@gated-at.bofh.it>
In reply to#1269453

[Multipart message — attachments visible in raw view] — view raw

Hi,

On 11/7/25 20:36, Adam D Barratt wrote:
> Package: curl
> Version: 8.14.1-2+deb13u1
> 
> Explanation: fix buffer over-read issue [CVE-2025-9086]; fix cache poisoning issue [CVE-2025-10148]; fix path traversal issue [CVE-2025-10148]; allow --output to be overridden by --curl-options; fix manpage example for "continue-at"


https://release.debian.org/proposed-updates/stable.html shows a 
regression (4 tries, the test doesn't seem to have a flaky history) in 
mpd on s390x. Now I'm not really worried that people use mpd on s390x, 
but it might indicate a subtle issue with curl on s390x. Care to have a 
look? I've CC'd the mpd maintainers as they might be able to tell what 
failure they are observing in their test. I also CC'd the s390x porters 
as they might care about curl behavior on s390x.

Paul

PS: the other "regressions" will go away when the page is refreshed as 
they all passed on retry or are flaky tests.

[toc] | [prev] | [next] | [standalone]


#1269637 — Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance

FromAdrian Bunk <bunk@debian.org>
Date2025-11-09 14:20 +0100
SubjectBug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance
Message-ID<LPduN-bF7o-3@gated-at.bofh.it>
In reply to#1269629
On Sun, Nov 09, 2025 at 11:56:19AM +0100, Paul Gevers wrote:
> Hi,
> 
> On 11/7/25 20:36, Adam D Barratt wrote:
> > Package: curl
> > Version: 8.14.1-2+deb13u1
> > 
> > Explanation: fix buffer over-read issue [CVE-2025-9086]; fix cache poisoning issue [CVE-2025-10148]; fix path traversal issue [CVE-2025-10148]; allow --output to be overridden by --curl-options; fix manpage example for "continue-at"
> 
> 
> https://release.debian.org/proposed-updates/stable.html shows a regression
> (4 tries, the test doesn't seem to have a flaky history) in mpd on s390x.
> Now I'm not really worried that people use mpd on s390x, but it might
> indicate a subtle issue with curl on s390x. Care to have a look? I've CC'd
> the mpd maintainers as they might be able to tell what failure they are
> observing in their test. I also CC'd the s390x porters as they might care
> about curl behavior on s390x.

Migration references are not retried for pu->stable, and when I did so 
manually it also failed:
https://ci.debian.net/packages/m/mpd/stable/s390x/

But this reference failure is in a different test...

Failure also previously happened in testing last month:
https://ci.debian.net/packages/m/mpd/testing/s390x/

After a manual retry mpd reference tests also fail in testing
and bookworm. In unstable it failed on 3rd attempt.

The latter indicates that mpd/s390x is flaky.

> Paul
>...

cu
Adrian

[toc] | [prev] | [next] | [standalone]


#1269648 — Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance

FromPaul Gevers <elbrus@debian.org>
Date2025-11-09 17:20 +0100
SubjectBug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance
Message-ID<LPgiZ-bHiy-13@gated-at.bofh.it>
In reply to#1269637

[Multipart message — attachments visible in raw view] — view raw

Hi Adrian

On 11/9/25 14:08, Adrian Bunk wrote:
> On Sun, Nov 09, 2025 at 11:56:19AM +0100, Paul Gevers wrote:
>> https://release.debian.org/proposed-updates/stable.html shows a regression
>> (4 tries, the test doesn't seem to have a flaky history) in mpd on s390x.
>> Now I'm not really worried that people use mpd on s390x, but it might
>> indicate a subtle issue with curl on s390x. Care to have a look? I've CC'd
>> the mpd maintainers as they might be able to tell what failure they are
>> observing in their test. I also CC'd the s390x porters as they might care
>> about curl behavior on s390x.
> 
> Migration references are not retried for pu->stable,


Depends on what you mean here. Britney2 for pu->stable is configure to 
retry in a similar way as unstable->testing. As stable doesn't change 
that much references are valid for 15 day while in testing validity is 7 
days.

> and when I did so
> manually it also failed:
> https://ci.debian.net/packages/m/mpd/stable/s390x/


The last reference ran on 31 October and the history of the package was 
very good, hence it didn't occur to me to retry. Thanks.

> Failure also previously happened in testing last month:
> https://ci.debian.net/packages/m/mpd/testing/s390x/


But this was a single incident and on retry that passed.

> After a manual retry mpd reference tests also fail in testing
> and bookworm. In unstable it failed on 3rd attempt.
> 
> The latter indicates that mpd/s390x is flaky.


The older history in s390x doesn't suggest that though. So this looks 
like fresh flakiness. Sorry for not considering that option.

Paul

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web