Bug 2511636 - CVE-2026-8458 davix: libcurl: Unauthorized connection reuse due to a logical error [epel-all]
Summary: CVE-2026-8458 davix: libcurl: Unauthorized connection reuse due to a logical ...
Keywords:
Status: ASSIGNED
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: davix
Version: epel10
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: Mihai Patrascoiu
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["ed295d65-c3e4-476d-bd8a-e...
Depends On:
Blocks: CVE-2026-8458
TreeView+ depends on / blocked
 
Reported: 2026-08-05 16:35 UTC by Rohit Keshri
Modified: 2026-08-06 07:27 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Rohit Keshri 2026-08-05 16:35:35 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

libcurl might in some circumstances reuse the wrong connection when asked to
do Negotiate-authenticated ones, even when they are set to use different
'services'.

libcurl features a pool of recent connections so that subsequent requests can
reuse an existing connection to avoid overhead.

When reusing a connection a range of criteria must be met. Due to a logical
error in the code, a request that was issued by an application could
wrongfully reuse an existing connection to the same server that was
authenticated using different services.

Comment 1 Mihai Patrascoiu 2026-08-06 07:27:41 UTC
Hello,

This CVE affects Davix on EPEL8 platform, as over there we bundle libcurl v7.69.0.

Can patch our Davix codebase once upstream patch backport is published for curl v7.69.0.

Cheers,
Mihai


Note You need to log in before you can comment on or make changes to this bug.