Alerts This Week
Warning Icon 1 815
Alerts This Week
Warning Icon 1 815

Ubuntu 25.10 curl Critical DoS and Authentication Issues USN-8062-1

ubuntu
Calendar Grey February 25, 2026
Dist Ubuntu Esm H88
Critical security issues in curl lead to potential information theft and denial of service. Update Ubuntu to mitigate risks.
Several security issues were fixed in curl.

Summary

Several security issues were fixed in curl.

Software Description:

- curl: HTTP, HTTPS, and FTP client and client libraries

Details:

It was discovered that curl incorrectly handled cookies when redirected

from secure to insecure connections. An attacker could possibly use this

issue to cause a denial of service, or obtain sensitive information.

This issue only affected Ubuntu 25.10. (CVE-2025-9086)

Calvin Ruocco discovered that curl did not properly handle WebSocket

communications under certain circumstances. A malicious server could

possibly use this issue to poison proxy caches with malicious content.

This issue only affected Ubuntu 24.04 LTS and Ubuntu 25.10.

(CVE-2025-10148)

Stanislav Fort discovered that wcurl did not properly handle URLs with

certain encoded characters. If a user were tricked into processing

a specially crafted URL, an attacker could possibly use this issue to

write files outside the intended directory. This issue only affected

Ubuntu 25.10. (CVE-2025-115...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 25.10
  curl                            8.14.1-2ubuntu1.1
  libcurl3t64-gnutls              8.14.1-2ubuntu1.1
  libcurl4-gnutls-dev             8.14.1-2ubuntu1.1
  libcurl4-openssl-dev            8.14.1-2ubuntu1.1
  libcurl4t64                     8.14.1-2ubuntu1.1

Ubuntu 24.04 LTS
  curl                            8.5.0-2ubuntu10.7
  libcurl3t64-gnutls              8.5.0-2ubuntu10.7
  libcurl4-gnutls-dev             8.5.0-2ubuntu10.7
  libcurl4-openssl-dev            8.5.0-2ubuntu10.7
  libcurl4t64                     8.5.0-2ubuntu10.7

Ubuntu 22.04 LTS
  curl                            7.81.0-1ubuntu1.22
  libcurl3-gnutls                 7.81.0-1ubuntu1.22
  libcurl3-nss                    7.81.0-1ubuntu1.22
  libcurl4                        7.81.0-1ubuntu1.22
  libcurl4-gnutls-dev             7.81.0-1ubuntu1.22
  libcurl4-nss-dev                7.81.0-1ubuntu1.22
  libcurl4-openssl-dev            7.81.0-1ubuntu1.22

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8062-1

CVE-2025-10148, CVE-2025-11563, CVE-2025-13034, CVE-2025-14017,

CVE-2025-14524, CVE-2025-14819, CVE-2025-15079, CVE-2025-15224,

CVE-2025-9086

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8062-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here