Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1269285

Bug#1120262: trixie-pu: package curl/8.14.1-2+deb13u1

From Alex <alex@puer-robustus.eu>
Newsgroups linux.debian.bugs.dist, linux.debian.devel.release
Subject Bug#1120262: trixie-pu: package curl/8.14.1-2+deb13u1
Date 2025-11-06 14:40 +0100
Message-ID <LO8nv-aVFX-3@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

Package: release.debian.org
Severity: normal
Tags: trixie
X-Debbugs-Cc: curl@packages.debian.org
Control: affects -1 + src:curl
User: release.debian.org@packages.debian.org
Usertags: pu

[ Reason ]

The curl package version in Debian Trixie suffers from three minor CVEs:

[1]: https://security-tracker.debian.org/tracker/CVE-2025-9086
[2]: https://security-tracker.debian.org/tracker/CVE-2025-10148
[3]: https://security-tracker.debian.org/tracker/CVE-2025-11563

The updated package version contains the backported upstream patches to
close those vulnerabilities and also two bug fixes for wcurl: a man page fix
and a fix to allow overriding the output file name with --curl-options.

[ Impact ]

If the update is not approved, all curl installations on Debian Trixie
machines will remain vulnerable to the exploits:

- CVE-2025-9086 allows for an out-of-bound read for cookie path
- A fixed mask pattern discovered in CVE-2025-10148 allows a malicious
  server to induce traffic between the two communicating parties that
  could be interpreted by an involved proxy (configured or transparent)
  as genuine, real, HTTP traffic with content and thereby poison its
  cache. That cached poisoned content could then be served to all users
  of that proxy.
- CVE-2025-11563 is a path traversal vulnerability where users might end up
  with the downloaded files placed in a folder outside of the current working
  directory unintentionally.

Regarding the additional wcurl fixes:
- The manpage fix is for an example invocation where the user wants downloads
  to be resumed, it's an important use case and was reported by a user.
- The fix for overriding the output filename with --curl-options is not that
  important, given users will use --output directly, but the fix is extremely
  straightforward.

[ Tests ]

All upstream tests run successfully.
Samuel Henrique <samueloph> has also run the reproducer for CVE-2025-9086
manually and confirmed that the patch fixes the issue.

[ Risks ]

Errors in backporting the patches which either don't close the
vulnerabilities or introduce regressions which are not caught by the
upstream tests.

The cookie handling patch with the fix for CVE-2025-9086 could be
carried over as is from upstream:
https://salsa.debian.org/debian/curl/-/commit/700cf2ca7aa6b461c37f28f4f2634850dbf3b971

The websocket patch for CVE-2025-10148 required some backporting to make
the expected return types match:
https://salsa.debian.org/debian/curl/-/commit/98f245da1dee1f4c549cd3b826a8bcc49cb03d71

The wcurl patches only required minimal backporting changes:
https://salsa.debian.org/debian/curl/-/commit/a50e1fa30dd7a58af13d4ce029352520b4e20dd1
https://salsa.debian.org/debian/curl/-/commit/84b76ed84665be069b70b14b0a857a6440708d9b
https://salsa.debian.org/debian/curl/-/commit/84e8794b04007dbc07db29ea3b3ab66873339986

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

[ Changes ]

* Backported patch to not drop leading slash in cookie path if that is
  its only component.
* Backported patch which ensures the use of a new, random mask for each
  outgoing frame on websockets.
* Backported wcurl patches for the CVE, manpage fix, and output filename
  overriding fix.
* salsa-ci.yml: Disable arm builds, they are currently broken.

[ Other info ]
Nothing that I am aware of.

Back to linux.debian.bugs.dist | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

Bug#1120262: trixie-pu: package curl/8.14.1-2+deb13u1 Alex <alex@puer-robustus.eu> - 2025-11-06 14:40 +0100
  Bug#1120262: trixie-pu: package curl/8.14.1-2+deb13u1 "Adam D. Barratt" <adam@adam-barratt.org.uk> - 2025-11-06 20:20 +0100
  Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance Adam D Barratt <adam@adam-barratt.org.uk> - 2025-11-07 20:40 +0100
    Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance Paul Gevers <elbrus@debian.org> - 2025-11-09 12:00 +0100
      Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance Adrian Bunk <bunk@debian.org> - 2025-11-09 14:20 +0100
        Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance Paul Gevers <elbrus@debian.org> - 2025-11-09 17:20 +0100

csiph-web