Bug 2394750 (CVE-2025-9086) - CVE-2025-9086 curl: libcurl: Curl out of bounds read for cookie path
Summary: CVE-2025-9086 curl: libcurl: Curl out of bounds read for cookie path
Keywords:
Status: NEW
Alias: CVE-2025-9086
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2394877 2394878 2394879 2394881 2394885 2394886 2394880 2394882 2394883 2394884
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-09-12 06:01 UTC by OSIDB Bzimport
Modified: 2026-02-23 22:59 UTC (History)
22 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2025:23681 0 None None None 2025-12-18 18:34:20 UTC
Red Hat Product Errata RHBA-2025:23698 0 None None None 2025-12-18 20:13:57 UTC
Red Hat Product Errata RHBA-2025:23748 0 None None None 2025-12-22 01:18:07 UTC
Red Hat Product Errata RHBA-2025:23753 0 None None None 2025-12-22 01:30:35 UTC
Red Hat Product Errata RHBA-2026:0028 0 None None None 2026-01-05 03:23:54 UTC
Red Hat Product Errata RHBA-2026:0055 0 None None None 2026-01-05 11:41:43 UTC
Red Hat Product Errata RHBA-2026:0057 0 None None None 2026-01-05 11:44:11 UTC
Red Hat Product Errata RHBA-2026:0068 0 None None None 2026-01-05 11:20:46 UTC
Red Hat Product Errata RHBA-2026:0209 0 None None None 2026-01-07 09:43:10 UTC
Red Hat Product Errata RHBA-2026:0387 0 None None None 2026-01-08 17:06:05 UTC
Red Hat Product Errata RHBA-2026:0388 0 None None None 2026-01-08 17:29:25 UTC
Red Hat Product Errata RHSA-2025:23043 0 None None None 2025-12-10 16:11:21 UTC
Red Hat Product Errata RHSA-2025:23125 0 None None None 2025-12-11 12:46:06 UTC
Red Hat Product Errata RHSA-2025:23126 0 None None None 2025-12-11 13:20:07 UTC
Red Hat Product Errata RHSA-2025:23127 0 None None None 2025-12-11 13:35:54 UTC
Red Hat Product Errata RHSA-2025:23383 0 None None None 2025-12-18 11:57:20 UTC
Red Hat Product Errata RHSA-2026:1350 0 None None None 2026-01-27 15:11:20 UTC
Red Hat Product Errata RHSA-2026:1477 0 None None None 2026-01-28 09:41:13 UTC
Red Hat Product Errata RHSA-2026:1825 0 None None None 2026-02-03 15:30:45 UTC

Description OSIDB Bzimport 2025-09-12 06:01:28 UTC
1. A cookie is set using the `secure` keyword for `https://target`
2. curl is redirected to or otherwise made to speak with `http://target` (same
   hostname, but using clear text HTTP) using the same cookie set
3. The same cookie name is set - but with just a slash as path (`path='/'`).
   Since this site is not secure, the cookie *should* just be ignored.
4. A bug in the path comparison logic makes curl read outside a heap buffer
   boundary

The bug either causes a crash or it potentially makes the comparison come to
the wrong conclusion and lets the clear-text site override the contents of the
secure cookie, contrary to expectations and depending on the memory contents
immediately following the single-byte allocation that holds the path.

The presumed and correct behavior would be to plainly ignore the second set of
the cookie since it was already set as secure on a secure host so overriding
it on an insecure host should not be okay.

Comment 3 errata-xmlrpc 2025-12-10 16:11:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2025:23043 https://access.redhat.com/errata/RHSA-2025:23043

Comment 4 errata-xmlrpc 2025-12-11 12:46:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:23125 https://access.redhat.com/errata/RHSA-2025:23125

Comment 5 errata-xmlrpc 2025-12-11 13:20:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:23126 https://access.redhat.com/errata/RHSA-2025:23126

Comment 6 errata-xmlrpc 2025-12-11 13:35:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2025:23127 https://access.redhat.com/errata/RHSA-2025:23127

Comment 7 errata-xmlrpc 2025-12-18 11:57:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:23383 https://access.redhat.com/errata/RHSA-2025:23383

Comment 8 errata-xmlrpc 2026-01-27 15:11:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:1350 https://access.redhat.com/errata/RHSA-2026:1350

Comment 9 errata-xmlrpc 2026-01-28 09:41:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:1477 https://access.redhat.com/errata/RHSA-2026:1477

Comment 12 errata-xmlrpc 2026-02-03 15:30:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:1825 https://access.redhat.com/errata/RHSA-2026:1825


Note You need to log in before you can comment on or make changes to this bug.