UBUNTU-CVE-2026-80229
Dashboard / Vulnerabilities / UBUNTU-CVE-2026-80229
UBUNTU-CVE-2026-80229
Summary:
Details: When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy handle's state and passes it to OpenSSL without acquiring an ownership reference; destroying the easy handle prematurely frees this context while the active connection retains a dangling pointer, leading to a heap-use-after-free upon subsequent I/O or post-handshake operations.
References: https://ubuntu.com/security/CVE-2026-80229, https://www.cve.org/CVERecord?id=CVE-2026-80229, https://curl.se/docs/CVE-2026-80229.html, https://github.com/curl/curl/commit/7ea37abc6ac0120ba5f6d9, https://ubuntu.com/security/notices/USN-8820-1
Affected packages
Package
Name: curl
Purl: pkg:deb/ubuntu/curl?arch=source&distro=resolute
Affected ranges
Type: ECOSYSTEM
Events:
