PT-2025-54486 · Suse+6 · Suse Linux Enterprise Server 15 Sp4+6
Daniel Stenberg
+1
·
Published
2025-01-01
·
Updated
2026-05-04
·
CVE-2025-14017
CVSS v3.1
6.3
Medium
| Vector | AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
libcurl versions prior to 7.87.0-150400.7.26.1
openSUSE Leap 15.6 (affected versions not specified)
SUSE Linux Enterprise Server 15 SP4 (affected versions not specified)
Description
The issue relates to libcurl's handling of TLS options during multi-threaded LDAPS (LDAP over TLS) transfers. Modifying TLS options within one thread unintentionally alters them globally, potentially impacting other concurrent transfers. Specifically, disabling certificate verification for a single transfer could inadvertently disable it for all threads. This could lead to insecure connections and potential compromise of sensitive data. The issue is also described as a heap buffer overflow in curl, potentially allowing Remote Code Execution (RCE) via malicious SOCKS5 proxy responses.
Recommendations
Update libcurl to version 7.87.0-150400.7.26.1 or later.
Apply the security update SUSE-2026-0078-1.
Update openSUSE Leap 15.6 to the latest available version.
Update SUSE Linux Enterprise Server 15 SP4 to the latest available version.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Linuxmint
Red Os
Suse Linux Enterprise Server 15 Sp4
Ubuntu
Libcurl
Opensuse Leap 15.6