Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed.
Hello, The CVE-2026-9080 vulnerability impacts curl versions 8.13.0 --> 8.20.0. Davix embeds curl v7.69.0 for EPEL8, whereas for all other platforms it uses the system-provided curl. This vulnerability does not impact Davix. Closing. Cheers, Mihai