CVE-2026-5773
ADVISORY - debianSummary
libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a network transfer operation that was requested by an application could wrongfully reuse an existing SMB connection to the same server that was using a different "share" than the new subsequent transfer should. This could in unlucky situations lead to the download of the wrong file or the upload of a file to the wrong place. When this happens, the same credentials are used and the server name is the same.
- curl 8.20.0~rc2-1 [trixie] - curl 8.14.1-2+deb13u4 [bookworm] - curl 7.88.1-10+deb12u15 [bullseye] - curl (Minor issue; can be fixed in next update) https://curl.se/docs/CVE-2026-5773.html Introduced by: https://github.com/curl/curl/commit/aec2e865f06669b9cb5d26cc1148d70bc418b163 (curl-7_40_0) Fixed by: https://github.com/curl/curl/commit/74a169575d6412dc0ff532acdf94de35a6c2a571 (rc-8_20_0-2)
Common Weakness Enumeration (CWE)
Comparison Using Wrong Factors
Debian
-
| Package | Type | OS Name | OS Version | Affected Ranges | Fix Versions |
|---|---|---|---|---|---|
| debian/curl | deb | debian | 12 | <7.88.1-10+deb12u15 | 7.88.1-10+deb12u15 |
| debian/curl | deb | debian | 14 | <8.20.0~rc2-1 | 8.20.0~rc2-1 |
| debian/curl | deb | debian | unstable | <8.20.0~rc2-1 | 8.20.0~rc2-1 |
| debian/curl | deb | debian | 13 | <8.14.1-2+deb13u4 | 8.14.1-2+deb13u4 |
Severity and metrics
No CVSS data available from this advisory.
NIST
CVSS SCORE
7.5highAlpine
-
Ubuntu
3.9
CVSS SCORE
7.5lowRed Hat
3.9
CVSS SCORE
6.5mediumPhoton
CVE-2026-5773
-
CVSS SCORE
7.5highminimos
MINI-h4jq-xcr6-grr6
-
minimos
MINI-rpcf-hgm3-fwch
-