A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET curl would use a heap-allocated struct after it had been freed in its transfer shutdown code path.
🔗 CVE IDs covered (1)
📋 Description
What is the curl open-source project? Curl is a computer software project providing a library (libcurl) and command-line tool (curl) for transferring data using various network protocols. The name stands for "Client for URL". The Windows implementation provides access to the command-line tool, not the library. What version of curl addresses this CVE? Curl version 7.87.0 addresses this vulnerability. Where can I find more information about this curl vulnerability? More information can be found at NVD and curl.se Are there any workarounds that can be implemented? Preventing the execution of curl.exe is a workaround to be considered Use a WDAC policy to deny execution of the \system32\curl.exe executable. You can merge the deny into an existing policy or create a new policy with it using the Merge-CIPolicy cmdlet; Merge-CIPolicy (ConfigCI) | Microsoft Learn. Once the policy XML file with the deny has been created or merged with an existing policy it must be deployed. Choose how to deploy the policy; Deploying Windows Defender Application Control (WDAC) policies | Microsoft Learn Deploy using a Mobile Device Management (MDM) solution, such as Microsoft Intune Deploy using Microsoft Configuration Manager Deploy via script Deploy via group policy For example: Create a new policy: (These steps will create a new policy named Deny-Curl.xml by merging the deny using the example policy named AllowAll.xml) $rule = new-cipolicyrule -DriverFilePath "$env:systemroot\system32\curl.exe" -Level FilePublisher -Deny $rule[0].attributes["MinimumFileVersion"] = "0.0.0.0" $rule[0].attributes["MaximumFileVersion"] = "7.87.0.0" merge-cipolicy "$env:systemroot\schemas\CodeIntegrity\ExamplePolicies\AllowAll.xml" -Rules $rule -OutputFilePath "Deny-Curl.xml" Merge into an existing policy $rule = new-cipolicyrule -DriverFilePath "$env:systemroot\system32\curl.exe" -Level FilePublisher -Deny $rule[0].attributes["MinimumFileVersion"] = "0.0.0.0" $rule[0].attributes["MaximumFileVersion"] = "7.87.0.0" merge-cipolicy "existing_policy.xml" -Rules $rule -OutputFilePath "existing_policy.xml" How to undo this workaround? Guidance for how to remove WDAC policies can be found in the following documentation: Remove Windows Defender Application Control (WDAC) policies
Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
🎯 Affected products12
- azl3 cmake 3.21.4-10 on Azure Linux 3.0
- azl3 cmake 3.28.2-1 on Azure Linux 3.0
- azl3 tensorflow 2.11.1-1 on Azure Linux 3.0
- azl3 tensorflow 2.16.1-1 on Azure Linux 3.0
- cbl2 cmake 3.21.4-13 on CBL Mariner 2.0
- cbl2 curl 7.86.0-3 on CBL Mariner 2.0
- cbl2 mysql 8.0.33-1 on CBL Mariner 2.0
- cbl2 rust 1.72.0-2 on CBL Mariner 2.0
- cm1 cmake 3.21.4-3 on CBL Mariner 1.0
- cm1 curl 7.86.0-3 on CBL Mariner 1.0
- cm1 mysql 8.0.32-1 on CBL Mariner 1.0
- cm1 rust 1.59.0-1 on CBL Mariner 1.0
✅ Remediation
KBCBL-Mariner Releases (Security Update) — fixed build 3.28.2-1 KBCBL-Mariner Releases (Security Update) — fixed build 1.59.0-1 KBCBL-Mariner Releases (Security Update) — fixed build 8.0.32-1 KBCBL-Mariner Releases (Security Update) — fixed build 7.86.0-3 KBCBL-Mariner Releases (Security Update) — fixed build 3.21.4-3 KBCBL-Mariner Releases (Security Update) — fixed build 1.72.0-2 KBCBL-Mariner Releases (Security Update) — fixed build 8.0.33-1 KBCBL-Mariner Releases (Security Update) — fixed build 3.21.4-13 KBCBL-Mariner Releases (Security Update) — fixed build 2.16.1-1