This update for curl fixes the following issues:
This update for curl fixes the following issues:
- CVE-2025-14017: broken TLS options for threaded LDAPS (bsc#1256105).
- CVE-2025-14524: bearer token leak on cross-protocol redirect (bsc#1255731).
- CVE-2025-14819: libssh global knownhost override (bsc#1255732).
- CVE-2025-15079: libssh key passphrase bypass without agent set (bsc#1255733).
- CVE-2025-15224: OpenSSL partial chain store policy bypass (bsc#1255734).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-140=1
- openSUSE Leap 16.0:
curl-8.14.1-160000.4.1
curl-fish-completion-8.14.1-160000.4.1
curl-zsh-completion-8.14.1-160000.4.1
libcurl-devel-8.14.1-160000.4.1
libcurl-devel-doc-8.14.1-160000.4.1
libcurl4-8.14.1-160000.4.1
* bsc#1255731
* bsc#1255732
* bsc#1255733
* bsc#1255734
* bsc#1256105
References:
* https://www.suse.com/security/cve/CVE-2025-14017.html
* https://www.suse.com/security/cve/CVE-2025-14524.html
* https://www.suse.com/security/cve/CVE-2025-14819.html
* https://www.suse.com/security/cve/CVE-2025-15079.html
* https://www.suse.com/security/cve/CVE-2025-15224.html
Get the latest Linux and open source security news straight to your inbox.