Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1269285
| From | Alex <alex@puer-robustus.eu> |
|---|---|
| Newsgroups | linux.debian.bugs.dist, linux.debian.devel.release |
| Subject | Bug#1120262: trixie-pu: package curl/8.14.1-2+deb13u1 |
| Date | 2025-11-06 14:40 +0100 |
| Message-ID | <LO8nv-aVFX-3@gated-at.bofh.it> (permalink) |
| Organization | linux.* mail to news gateway |
Cross-posted to 2 groups.
[Multipart message — attachments visible in raw view] - view raw
Package: release.debian.org Severity: normal Tags: trixie X-Debbugs-Cc: curl@packages.debian.org Control: affects -1 + src:curl User: release.debian.org@packages.debian.org Usertags: pu [ Reason ] The curl package version in Debian Trixie suffers from three minor CVEs: [1]: https://security-tracker.debian.org/tracker/CVE-2025-9086 [2]: https://security-tracker.debian.org/tracker/CVE-2025-10148 [3]: https://security-tracker.debian.org/tracker/CVE-2025-11563 The updated package version contains the backported upstream patches to close those vulnerabilities and also two bug fixes for wcurl: a man page fix and a fix to allow overriding the output file name with --curl-options. [ Impact ] If the update is not approved, all curl installations on Debian Trixie machines will remain vulnerable to the exploits: - CVE-2025-9086 allows for an out-of-bound read for cookie path - A fixed mask pattern discovered in CVE-2025-10148 allows a malicious server to induce traffic between the two communicating parties that could be interpreted by an involved proxy (configured or transparent) as genuine, real, HTTP traffic with content and thereby poison its cache. That cached poisoned content could then be served to all users of that proxy. - CVE-2025-11563 is a path traversal vulnerability where users might end up with the downloaded files placed in a folder outside of the current working directory unintentionally. Regarding the additional wcurl fixes: - The manpage fix is for an example invocation where the user wants downloads to be resumed, it's an important use case and was reported by a user. - The fix for overriding the output filename with --curl-options is not that important, given users will use --output directly, but the fix is extremely straightforward. [ Tests ] All upstream tests run successfully. Samuel Henrique <samueloph> has also run the reproducer for CVE-2025-9086 manually and confirmed that the patch fixes the issue. [ Risks ] Errors in backporting the patches which either don't close the vulnerabilities or introduce regressions which are not caught by the upstream tests. The cookie handling patch with the fix for CVE-2025-9086 could be carried over as is from upstream: https://salsa.debian.org/debian/curl/-/commit/700cf2ca7aa6b461c37f28f4f2634850dbf3b971 The websocket patch for CVE-2025-10148 required some backporting to make the expected return types match: https://salsa.debian.org/debian/curl/-/commit/98f245da1dee1f4c549cd3b826a8bcc49cb03d71 The wcurl patches only required minimal backporting changes: https://salsa.debian.org/debian/curl/-/commit/a50e1fa30dd7a58af13d4ce029352520b4e20dd1 https://salsa.debian.org/debian/curl/-/commit/84b76ed84665be069b70b14b0a857a6440708d9b https://salsa.debian.org/debian/curl/-/commit/84e8794b04007dbc07db29ea3b3ab66873339986 [ Checklist ] [x] *all* changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in (old)stable [x] the issue is verified as fixed in unstable [ Changes ] * Backported patch to not drop leading slash in cookie path if that is its only component. * Backported patch which ensures the use of a new, random mask for each outgoing frame on websockets. * Backported wcurl patches for the CVE, manpage fix, and output filename overriding fix. * salsa-ci.yml: Disable arm builds, they are currently broken. [ Other info ] Nothing that I am aware of.
Back to linux.debian.bugs.dist | Previous | Next — Next in thread | Find similar | Unroll thread
Bug#1120262: trixie-pu: package curl/8.14.1-2+deb13u1 Alex <alex@puer-robustus.eu> - 2025-11-06 14:40 +0100
Bug#1120262: trixie-pu: package curl/8.14.1-2+deb13u1 "Adam D. Barratt" <adam@adam-barratt.org.uk> - 2025-11-06 20:20 +0100
Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance Adam D Barratt <adam@adam-barratt.org.uk> - 2025-11-07 20:40 +0100
Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance Paul Gevers <elbrus@debian.org> - 2025-11-09 12:00 +0100
Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance Adrian Bunk <bunk@debian.org> - 2025-11-09 14:20 +0100
Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance Paul Gevers <elbrus@debian.org> - 2025-11-09 17:20 +0100
csiph-web