EulerOS 2.0 SP15 : curl (EulerOS-SA-2026-3969)

critical Nessus Plugin ID 364082

Synopsis

The remote EulerOS host is missing multiple security updates.

Description

According to the versions of the curl packages installed, the EulerOS installation on the remote host is affected by the following vulnerabilities :

A use-after-free vulnerability exists in libcurl when an application_x000D_ configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or_x000D_ `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and_x000D_ finally terminates the handle with `curl_easy_cleanup()`. During this final_x000D_ cleanup phase, libcurl attempts to access and modify an internal structure_x000D_ that was already freed during the reset operation.(CVE-2026-10536)

When a user invokes curl using a schemeless URL combined with_x000D_ `--proto-default` sftp (or scp), a disconnect occurs between the tool layer_x000D_ and libcurl. The tool layer incorrectly infers the URL scheme, which_x000D_ erroneously bypasses the initialization of critical SSH security options like_x000D_ CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the_x000D_ libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes_x000D_ the connection via SFTP/SCP as specified. Because the tool layer skipped the_x000D_ security configuration, these SSH host verification options are silently_x000D_ omitted, causing curl to connect to an unverified SSH remote host without_x000D_ throwing an error.(CVE-2026-12064)

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the_x000D_ connection might reuse an existing live connection even though the TLS_x000D_ configuration mismatches so it should not.(CVE-2026-8286)

When asking curl to use a `.netrc` file to find credentials and at the same_x000D_ time specifying a URL with a username(without a password), like_x000D_ `https://[email protected]/`, curl could wrongly get and use the password for_x000D_
*another* user set in the `.netrc` file for that host if such a one exists and_x000D_ there is no match for the specified user.(CVE-2026-8926)

When reusing a libcurl handle for sequential transfers driven by_x000D_ environment-variable proxy configuration, libcurl fails to clear the proxy_x000D_ authentication state between requests. Specifically, if the initial transfer_x000D_ authenticates against `proxyA` using Digest auth, a subsequent transfer routed_x000D_ through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended_x000D_ solely for `proxyA`.(CVE-2026-8927)

When a libcurl-based application performs transfers via `SCP://` or `SFTP://`_x000D_ and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an_x000D_ untrusted server. This vulnerability occurs when a server presents a host key_x000D_ type that does not match the specific key type already recorded for that host_x000D_ in the `known_hosts` file. Instead of rejecting the mismatch, the callback_x000D_ mechanism fails to properly enforce the restriction, allowing the connection_x000D_ to succeed without warning and risking a potential man-in-the-middle attack.(CVE-2026-9547)

A flaw in curl's cookie parsing logic allows a malicious HTTP server to set_x000D_ 'super cookies' that bypass the Public Suffix List check. This enables an_x000D_ attacker-controlled origin to inject cookies that curl subsequently scopes and_x000D_ transmits to unrelated third-party domains.(CVE-2026-8924)

Tenable has extracted the preceding description block directly from the EulerOS curl security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected curl packages.

See Also

http://www.nessus.org/u?e6dd1b08

Plugin Details

Severity: Critical

ID: 364082

File Name: EulerOS_SA-2026-3969.nasl

Version: 1.1

Type: Local

Published: 10/8/2026

Updated: 10/8/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.12

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-10536

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:huawei:euleros:2.0, p-cpe:/a:huawei:euleros:curl-help, p-cpe:/a:huawei:euleros:curl, p-cpe:/a:huawei:euleros:libcurl-devel, p-cpe:/a:huawei:euleros:libcurl

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/EulerOS/release, Host/EulerOS/rpm-list, Host/EulerOS/sp

Excluded KB Items: Host/EulerOS/uvp_version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/8/2026

Vulnerability Publication Date: 6/25/2026

Reference Information

CVE: CVE-2026-10536, CVE-2026-12064, CVE-2026-8286, CVE-2026-8924, CVE-2026-8926, CVE-2026-8927, CVE-2026-9547