USN-8820-1: curl vulnerabilities
What it means
Ubuntu ha rilasciato un avviso di sicurezza (USN-8820-1) riguardante vulnerabilità in curl. Le vulnerabilità interessano Ubuntu 18.04 LTS, 20.04 LTS, 22.04 LTS, 24.04 LTS e 26.04 LTS. Alcune vulnerabilità potrebbero permettere a un attaccante di bypassare la validazione del peer, causare un denial of service o eseguire codice arbitrario. Le patch sono disponibili per aggiornare i pacchetti interessati.
Why it matters
Le vulnerabilità in curl possono compromettere la sicurezza delle comunicazioni e dei dati sensibili, con rischi di esposizione di informazioni e interruzione del servizio. Per le PMI italiane, un attacco potrebbe danneggiare la reputazione e la continuità operativa.
Recommended actions
- Applica le patch disponibili per i pacchetti curl interessati (libcurl3, libcurl4, ecc.).
- Verifica l'aggiornamento di Ubuntu Pro per ottenere protezione aggiuntiva.
- Disattiva le connessioni HTTP/2 in ambiente di produzione se non necessarie.
- Implementa controlli di autenticazione LDAP aggiuntivi per mitigare attacchi MITM.
- Monitora l'uso di curl in applicazioni critiche e limita l'accesso a risorse sensibili.
- Esegui un audit delle configurazioni di curl per verificare l'uso corretto di certificati e cookie.
Potential operational benefits
- Riduzione della superficie esposta a vulnerabilità in curl.
- Miglioramento della protezione contro attacchi MITM e denial of service.
- Aumento della conformità alle normative di sicurezza e privacy.
Translation in progress
The official content is available in the original language. The Italian version will be published once automated checks are complete.
Text acquired from the source
Eunsoo Kim discovered that curl incorrectly handled SASL negotiation for LDAP authentication in certain circumstances. A machine-in-the-middle attacker could possibly use this issue to bypass peer validation. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-13608) Stephan Zeisberg discovered that curl incorrectly handled HTTP/2 Server Push streams when sharing connections between handles. A remote attacker could possibly use this issue to cause curl to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-18924) Stanislav Fort discovered that curl incorrectly managed the lifetime of pooled TLS connections when using the multi interface. An attacker could possibly use this issue to cause curl to crash, resulting in a denial of service, or execute arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-80229) Stanislav Fort discovered that curl did not properly enforce public key pinning when certificate verification was disabled in certain circumstances. A remote attacker could possibly use this issue to bypass pinning checks and cause curl to accept connections that should have been rejected. (CVE-2026-80230) Stanislav Fort discovered that curl incorrectly handled the Secure attribute of cookies in certain circumstances. A remote attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-80255) Stanislav Fort discovered that curl did not properly enforce Public Suffix List boundaries when handling cookies in certain circumstances. A remote attacker could possibly use this issue to cause cookies to be sent to unrelated domains, resulting in sensitive information being exposed. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 2
- Source
- Ubuntu Security Notices
- Publishing entity
- Ubuntu Security
- Entity type
- vendor security
- Area
- Global
- Original language
- en · translation in preparation
- Publication
- 24/09/2026 22:13
- MITRE ATT&CK
- T1562, T1486
- CVE
- CVE-2026-13608, CVE-2026-18924, CVE-2026-80229, CVE-2026-80230, CVE-2026-80255
Affected products and versions
The collector will check NVD and the available official vendor advisories.