PT-2025-54486 · Suse+6 · Suse Linux Enterprise Server 15 Sp4+6

Daniel Stenberg

+1

·

Published

2025-01-01

·

Updated

2026-05-04

·

CVE-2025-14017

CVSS v3.1

6.3

Medium

VectorAV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions libcurl versions prior to 7.87.0-150400.7.26.1 openSUSE Leap 15.6 (affected versions not specified) SUSE Linux Enterprise Server 15 SP4 (affected versions not specified)
Description The issue relates to libcurl's handling of TLS options during multi-threaded LDAPS (LDAP over TLS) transfers. Modifying TLS options within one thread unintentionally alters them globally, potentially impacting other concurrent transfers. Specifically, disabling certificate verification for a single transfer could inadvertently disable it for all threads. This could lead to insecure connections and potential compromise of sensitive data. The issue is also described as a heap buffer overflow in curl, potentially allowing Remote Code Execution (RCE) via malicious SOCKS5 proxy responses.
Recommendations Update libcurl to version 7.87.0-150400.7.26.1 or later. Apply the security update SUSE-2026-0078-1. Update openSUSE Leap 15.6 to the latest available version. Update SUSE Linux Enterprise Server 15 SP4 to the latest available version.

Fix

RCE

Weakness Enumeration

Related Identifiers

AZL-73676
AZL-73736
AZL-73740
AZL-73743
BDU:2026-05122
CVE-2025-14017
ECHO-8091-7FB3-2EA0
JLSEC-2026-427
MGASA-2026-0003
OPENSUSE-SU-2026:10017-1
OPENSUSE-SU-2026:20031-1
RHSA-2026:6893
SUSE-SU-2026:0077-1
SUSE-SU-2026:0078-1
SUSE-SU-2026:0119-1
SUSE-SU-2026:0221-1
SUSE-SU-2026:0508-1
SUSE-SU-2026:20082-1
SUSE-SU-2026:20110-1
SUSE-SU-2026:20347-1
SUSE-SU-2026:20358-1
USN-8062-1
USN-8062-2

Affected Products

Debian
Linuxmint
Red Os
Suse Linux Enterprise Server 15 Sp4
Ubuntu
Libcurl
Opensuse Leap 15.6