Bug 2498186 - CVE-2026-10536 davix: libcurl: Use-after-free vulnerability leading to Denial of Service [epel-all]
Summary: CVE-2026-10536 davix: libcurl: Use-after-free vulnerability leading to Denial...
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: davix
Version: epel10
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Mihai Patrascoiu
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["4d7b0ee2-22af-4746-a28b-1...
Depends On:
Blocks: CVE-2026-10536
TreeView+ depends on / blocked
 
Reported: 2026-07-08 18:25 UTC by Jon Moroney
Modified: 2026-07-14 13:14 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-07-14 13:14:36 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Jon Moroney 2026-07-08 18:25:22 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

A use-after-free vulnerability exists in libcurl when an application
configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or
`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and
finally terminates the handle with `curl_easy_cleanup()`. During this final
cleanup phase, libcurl attempts to access and modify an internal structure
that was already freed during the reset operation.

Comment 1 Mihai Patrascoiu 2026-07-14 13:14:36 UTC
Hello,

The CVE-2026-10536 vulnerability impacts curl versions 7.88.0 --> 8.20.0.
Davix embeds curl v7.69.0 for EPEL8, whereas for all other platforms it uses the system-provided curl, with no exact version pinned.

This vulnerability does not impact Davix on EPEL8.
On all other platforms, it is resolved by bringing a patched curl version.

Closing as not a vulnerability to address in Davix.

Cheers,
Mihai


Note You need to log in before you can comment on or make changes to this bug.