CVE-2026-8925
ADVISORY - debianSummary
The curl logic that works with SASL authentication could end up cleaning up the GSASL context twice without clearing the pointer in between, making it free() the same pointer twice.
- curl 8.21.0~rc2-1 [trixie] - curl (Vulnerable code not present) [bookworm] - curl (Vulnerable code not present) [bullseye] - curl (Vulnerable code not present) https://curl.se/docs/CVE-2026-8925.html Introduced with: https://github.com/curl/curl/commit/ab650379a8c25ca952f651476d25b4cdd77bb3fc (curl-8_15_0) Fixed by: https://github.com/curl/curl/commit/3da249e1f0716c06644ed3522a37a8bf81808012 (rc-8_21_0-1, curl-8_21_0)
EPSS Score: 0.0108 (0.614)
Common Weakness Enumeration (CWE)
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in