Bug 2496766 (CVE-2026-10536) - CVE-2026-10536 libcurl: libcurl: Use-after-free vulnerability leading to Denial of Service
Summary: CVE-2026-10536 libcurl: libcurl: Use-after-free vulnerability leading to Deni...
Keywords:
Status: NEW
Alias: CVE-2026-10536
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2507892 2507896 2507897 2498186 2507891 2507893 2507894 2507895 2507898 2507899
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-03 07:01 UTC by OSIDB Bzimport
Modified: 2026-08-31 10:17 UTC (History)
39 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:56869 0 None None None 2026-08-19 13:28:40 UTC

Description OSIDB Bzimport 2026-07-03 07:01:58 UTC
A use-after-free vulnerability exists in libcurl when an application
configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or
`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and
finally terminates the handle with `curl_easy_cleanup()`. During this final
cleanup phase, libcurl attempts to access and modify an internal structure
that was already freed during the reset operation.

Comment 4 errata-xmlrpc 2026-08-19 13:28:38 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Core Services 2.4.62.SP5

Via RHSA-2026:56869 https://access.redhat.com/errata/RHSA-2026:56869


Note You need to log in before you can comment on or make changes to this bug.