Bug 2394750 (CVE-2025-9086)

Summary: CVE-2025-9086 curl: libcurl: Curl out of bounds read for cookie path
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: akhatavk, aos-team-art-private, asdas, crizzo, csutherl, dbosanac, dpaolell, gtanzill, jbuscemi, jclere, jdelft, jmitchel, jreimann, jupierce, kshier, lgarciaa, mbiarnes, mdessi, mrizzi, pcattana, pjindal, plodge, ppalepu, ppostler, prdhamdh, rhel-process-autobot, sdawley, sghai, sidsharm, stcannon, suppawar, szappis, teagle, vchlup, vlaad, watson-tool-maintainers, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
An out of bounds read flaw has been discovered in the curl project. Under specific conditions the path comparison logic makes curl read outside a heap buffer boundary. This bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2394877, 2394878, 2394879, 2394880, 2394881, 2394882, 2394883, 2394884, 2394885, 2394886    
Bug Blocks:    

Description OSIDB Bzimport 2025-09-12 06:01:28 UTC
1. A cookie is set using the `secure` keyword for `https://target`
2. curl is redirected to or otherwise made to speak with `http://target` (same
   hostname, but using clear text HTTP) using the same cookie set
3. The same cookie name is set - but with just a slash as path (`path='/'`).
   Since this site is not secure, the cookie *should* just be ignored.
4. A bug in the path comparison logic makes curl read outside a heap buffer
   boundary

The bug either causes a crash or it potentially makes the comparison come to
the wrong conclusion and lets the clear-text site override the contents of the
secure cookie, contrary to expectations and depending on the memory contents
immediately following the single-byte allocation that holds the path.

The presumed and correct behavior would be to plainly ignore the second set of
the cookie since it was already set as secure on a secure host so overriding
it on an insecure host should not be okay.

Comment 3 errata-xmlrpc 2025-12-10 16:11:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2025:23043 https://access.redhat.com/errata/RHSA-2025:23043

Comment 4 errata-xmlrpc 2025-12-11 12:46:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:23125 https://access.redhat.com/errata/RHSA-2025:23125

Comment 5 errata-xmlrpc 2025-12-11 13:20:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:23126 https://access.redhat.com/errata/RHSA-2025:23126

Comment 6 errata-xmlrpc 2025-12-11 13:35:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2025:23127 https://access.redhat.com/errata/RHSA-2025:23127

Comment 7 errata-xmlrpc 2025-12-18 11:57:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:23383 https://access.redhat.com/errata/RHSA-2025:23383

Comment 8 errata-xmlrpc 2026-01-27 15:11:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:1350 https://access.redhat.com/errata/RHSA-2026:1350

Comment 9 errata-xmlrpc 2026-01-28 09:41:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:1477 https://access.redhat.com/errata/RHSA-2026:1477

Comment 12 errata-xmlrpc 2026-02-03 15:30:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:1825 https://access.redhat.com/errata/RHSA-2026:1825