Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:23126 - Security Advisory
Issued:
2025-12-11
Updated:
2025-12-11

RHSA-2025:23126 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: curl security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for curl is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.

Security Fix(es):

  • curl: libcurl: Curl out of bounds read for cookie path (CVE-2025-9086)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2394750 - CVE-2025-9086 curl: libcurl: Curl out of bounds read for cookie path

CVEs

  • CVE-2025-9086

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
curl-7.76.1-14.el9_0.12.src.rpm SHA-256: dedc821f6f299df3313d4d71f145524ee46bcbc2930f9e0f90c0c291c0160064
ppc64le
curl-7.76.1-14.el9_0.12.ppc64le.rpm SHA-256: e6da8b1424747baefd87b1d206c6d95f4d720ba8d80dd946ea492552222162d9
curl-debuginfo-7.76.1-14.el9_0.12.ppc64le.rpm SHA-256: 323190c8aaad62c8ad99d97f5dc84bfec1385c81750a136b72e8d66be7caac45
curl-debuginfo-7.76.1-14.el9_0.12.ppc64le.rpm SHA-256: 323190c8aaad62c8ad99d97f5dc84bfec1385c81750a136b72e8d66be7caac45
curl-debugsource-7.76.1-14.el9_0.12.ppc64le.rpm SHA-256: d91c902adb491113cb4c506b0d19013ce7ebd2755fa1cab3aa9046357f98561f
curl-debugsource-7.76.1-14.el9_0.12.ppc64le.rpm SHA-256: d91c902adb491113cb4c506b0d19013ce7ebd2755fa1cab3aa9046357f98561f
curl-minimal-7.76.1-14.el9_0.12.ppc64le.rpm SHA-256: bf2d6fce1a8149f4cfdfdce8f39302d4abaebfd735cd0e80931e272462fec49c
curl-minimal-debuginfo-7.76.1-14.el9_0.12.ppc64le.rpm SHA-256: 0a8e583d41bbf93824627d989aa4d7bada7f25d076f5073a193ee920c95d694b
curl-minimal-debuginfo-7.76.1-14.el9_0.12.ppc64le.rpm SHA-256: 0a8e583d41bbf93824627d989aa4d7bada7f25d076f5073a193ee920c95d694b
libcurl-7.76.1-14.el9_0.12.ppc64le.rpm SHA-256: 6590602df41293e2f1621a353ea2bbde71f75abcb5d07c20031bfe6528f71039
libcurl-debuginfo-7.76.1-14.el9_0.12.ppc64le.rpm SHA-256: 7a0c27d8d70c4a024a2b1d4a1cec4c6e60634583b2371435c52459873b34d691
libcurl-debuginfo-7.76.1-14.el9_0.12.ppc64le.rpm SHA-256: 7a0c27d8d70c4a024a2b1d4a1cec4c6e60634583b2371435c52459873b34d691
libcurl-devel-7.76.1-14.el9_0.12.ppc64le.rpm SHA-256: 0aa6450e1ecb422c58bcefd18efae00bce6d9244d9b45313643d8b64da052fb2
libcurl-minimal-7.76.1-14.el9_0.12.ppc64le.rpm SHA-256: 90c4c26a077a43065b650d4d7fc0a4d43e0adfb556b078f7380c68bd2b96bfec
libcurl-minimal-debuginfo-7.76.1-14.el9_0.12.ppc64le.rpm SHA-256: 6f431cc06cb614ed99eec463fa9c3045c56832ecb9016e04708b2222cf3fa540
libcurl-minimal-debuginfo-7.76.1-14.el9_0.12.ppc64le.rpm SHA-256: 6f431cc06cb614ed99eec463fa9c3045c56832ecb9016e04708b2222cf3fa540

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
curl-7.76.1-14.el9_0.12.src.rpm SHA-256: dedc821f6f299df3313d4d71f145524ee46bcbc2930f9e0f90c0c291c0160064
x86_64
curl-7.76.1-14.el9_0.12.x86_64.rpm SHA-256: 5549c069494171feca4aa7d60617ab70f3045e87780c1afbf2c485b3f4485bd1
curl-debuginfo-7.76.1-14.el9_0.12.i686.rpm SHA-256: 1d3bda58ac04e7c6057de1fa37462359252afb2d032f556a3b3be3cb908bac3c
curl-debuginfo-7.76.1-14.el9_0.12.i686.rpm SHA-256: 1d3bda58ac04e7c6057de1fa37462359252afb2d032f556a3b3be3cb908bac3c
curl-debuginfo-7.76.1-14.el9_0.12.x86_64.rpm SHA-256: 1fe98715c967c0ce73a2ad7c4e47c2f78e8ab80b34182ff8db32f501a7ac0721
curl-debuginfo-7.76.1-14.el9_0.12.x86_64.rpm SHA-256: 1fe98715c967c0ce73a2ad7c4e47c2f78e8ab80b34182ff8db32f501a7ac0721
curl-debugsource-7.76.1-14.el9_0.12.i686.rpm SHA-256: 223f852e863b589c1eabaa323d28a979e9fcf4652b9f5ca2dc1fde0b4dd8ba0f
curl-debugsource-7.76.1-14.el9_0.12.i686.rpm SHA-256: 223f852e863b589c1eabaa323d28a979e9fcf4652b9f5ca2dc1fde0b4dd8ba0f
curl-debugsource-7.76.1-14.el9_0.12.x86_64.rpm SHA-256: d8ef20cb66f6e1e6ac7eafec8a0cfd4a59a6697904f1fe87b4d8654131fd2499
curl-debugsource-7.76.1-14.el9_0.12.x86_64.rpm SHA-256: d8ef20cb66f6e1e6ac7eafec8a0cfd4a59a6697904f1fe87b4d8654131fd2499
curl-minimal-7.76.1-14.el9_0.12.x86_64.rpm SHA-256: 7d524e27a466f8a1646c3df18e43c7dd22ff28da7f72975df8365d22827b58ca
curl-minimal-debuginfo-7.76.1-14.el9_0.12.i686.rpm SHA-256: b5065332f2cf16a189327ff12052b520f4aeba01a3df913194d5b88df81c489b
curl-minimal-debuginfo-7.76.1-14.el9_0.12.i686.rpm SHA-256: b5065332f2cf16a189327ff12052b520f4aeba01a3df913194d5b88df81c489b
curl-minimal-debuginfo-7.76.1-14.el9_0.12.x86_64.rpm SHA-256: bd3ab1a7e81e0d23abf4db59ba7fb36aae83ad65acdfbfd6beec7ce1088d8e2a
curl-minimal-debuginfo-7.76.1-14.el9_0.12.x86_64.rpm SHA-256: bd3ab1a7e81e0d23abf4db59ba7fb36aae83ad65acdfbfd6beec7ce1088d8e2a
libcurl-7.76.1-14.el9_0.12.i686.rpm SHA-256: e72611c9f393768d365f03e4a069e0d4f5ddd62f29d743b14936d894af72c403
libcurl-7.76.1-14.el9_0.12.x86_64.rpm SHA-256: b96568931a0beea5fc94e4cf4e47b7295eb992fb4990c7e6fbd012bbd58721b3
libcurl-debuginfo-7.76.1-14.el9_0.12.i686.rpm SHA-256: 5bde124332a538fb29034608ff9f4a8734678c83996a82981355219a3aa6b3aa
libcurl-debuginfo-7.76.1-14.el9_0.12.i686.rpm SHA-256: 5bde124332a538fb29034608ff9f4a8734678c83996a82981355219a3aa6b3aa
libcurl-debuginfo-7.76.1-14.el9_0.12.x86_64.rpm SHA-256: 2691db05eac6f9ebf5830ac276da79f770280b12689734017cdf30781b1876bc
libcurl-debuginfo-7.76.1-14.el9_0.12.x86_64.rpm SHA-256: 2691db05eac6f9ebf5830ac276da79f770280b12689734017cdf30781b1876bc
libcurl-devel-7.76.1-14.el9_0.12.i686.rpm SHA-256: e087c63ee6d7c3d748bfe0a7590a5b61d2a4627fe811283e782571f5f657944d
libcurl-devel-7.76.1-14.el9_0.12.x86_64.rpm SHA-256: 6e6397748fce0af7bd7994a82c94cf118cfb395e45c675f9158551e92b87d74b
libcurl-minimal-7.76.1-14.el9_0.12.i686.rpm SHA-256: 2fed68c2486a037e968ed5152f8cea6a5dcc51a88157dcb651e9c7aa5c09b00a
libcurl-minimal-7.76.1-14.el9_0.12.x86_64.rpm SHA-256: fce075e70614a6757a43183d5212fb09bf45eaa13f654399d965183a40e357c5
libcurl-minimal-debuginfo-7.76.1-14.el9_0.12.i686.rpm SHA-256: b7898fac275ea892fc72d721a116f5fe1e1d56c3608dca52ffbb39bbc0b20ff8
libcurl-minimal-debuginfo-7.76.1-14.el9_0.12.i686.rpm SHA-256: b7898fac275ea892fc72d721a116f5fe1e1d56c3608dca52ffbb39bbc0b20ff8
libcurl-minimal-debuginfo-7.76.1-14.el9_0.12.x86_64.rpm SHA-256: 2a7732fe4755f3fc23e5a28663dfcd02025dbd09c39394c4c5af9a6e1546389c
libcurl-minimal-debuginfo-7.76.1-14.el9_0.12.x86_64.rpm SHA-256: 2a7732fe4755f3fc23e5a28663dfcd02025dbd09c39394c4c5af9a6e1546389c

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
curl-7.76.1-14.el9_0.12.src.rpm SHA-256: dedc821f6f299df3313d4d71f145524ee46bcbc2930f9e0f90c0c291c0160064
aarch64
curl-7.76.1-14.el9_0.12.aarch64.rpm SHA-256: c772677bb3b3ad9eebd8f273b6056ee7a47db25f4bba0af296b686772dad2fcd
curl-debuginfo-7.76.1-14.el9_0.12.aarch64.rpm SHA-256: c50ed00881dde3f51d294891835fbc803167a396fa4864fd34b38e5b5753526d
curl-debuginfo-7.76.1-14.el9_0.12.aarch64.rpm SHA-256: c50ed00881dde3f51d294891835fbc803167a396fa4864fd34b38e5b5753526d
curl-debugsource-7.76.1-14.el9_0.12.aarch64.rpm SHA-256: 54998b1cb9d4b8660440b96acb55701a57f07bced995ada7d9f94b7049da8d2a
curl-debugsource-7.76.1-14.el9_0.12.aarch64.rpm SHA-256: 54998b1cb9d4b8660440b96acb55701a57f07bced995ada7d9f94b7049da8d2a
curl-minimal-7.76.1-14.el9_0.12.aarch64.rpm SHA-256: 8b0d71472ec85e7a87764c70063369c5c386b94a0674440af0125325721a053d
curl-minimal-debuginfo-7.76.1-14.el9_0.12.aarch64.rpm SHA-256: 78e020c09131f685e8c2654de36dcfe1be3beeff3845ba007b44ce13ae7c606d
curl-minimal-debuginfo-7.76.1-14.el9_0.12.aarch64.rpm SHA-256: 78e020c09131f685e8c2654de36dcfe1be3beeff3845ba007b44ce13ae7c606d
libcurl-7.76.1-14.el9_0.12.aarch64.rpm SHA-256: fee15fa067c0a3966add077a51263dd98724b88a68e18d4229ac5d11655168ec
libcurl-debuginfo-7.76.1-14.el9_0.12.aarch64.rpm SHA-256: e205de9ff8f6c17bc485c1cb4ff44a5d48fd356b6076cf6befccaa7579ecbcb4
libcurl-debuginfo-7.76.1-14.el9_0.12.aarch64.rpm SHA-256: e205de9ff8f6c17bc485c1cb4ff44a5d48fd356b6076cf6befccaa7579ecbcb4
libcurl-devel-7.76.1-14.el9_0.12.aarch64.rpm SHA-256: 3f4c86d58517e6606c9fcd169f5f6d870c646ec83f75c47c0a7d20f21442cafd
libcurl-minimal-7.76.1-14.el9_0.12.aarch64.rpm SHA-256: f189fd1228b0ee9d082c44f00bef7c4fcac3a65afe6fb5a1f95bec6d9ef4995c
libcurl-minimal-debuginfo-7.76.1-14.el9_0.12.aarch64.rpm SHA-256: d3ee8e4b586886b15b1eb6d0d806fce2a36fd4478f9c0c460491dae959066b7f
libcurl-minimal-debuginfo-7.76.1-14.el9_0.12.aarch64.rpm SHA-256: d3ee8e4b586886b15b1eb6d0d806fce2a36fd4478f9c0c460491dae959066b7f

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
curl-7.76.1-14.el9_0.12.src.rpm SHA-256: dedc821f6f299df3313d4d71f145524ee46bcbc2930f9e0f90c0c291c0160064
s390x
curl-7.76.1-14.el9_0.12.s390x.rpm SHA-256: be2f34fd449c2170e1751691b93c68b30936b9e2684c9a0d4afe31fdc6e9e091
curl-debuginfo-7.76.1-14.el9_0.12.s390x.rpm SHA-256: bbd0c731ff50c504412d2f7ec96667d5a2c336d4adf00abfd8ee1f7d0bdf2509
curl-debuginfo-7.76.1-14.el9_0.12.s390x.rpm SHA-256: bbd0c731ff50c504412d2f7ec96667d5a2c336d4adf00abfd8ee1f7d0bdf2509
curl-debugsource-7.76.1-14.el9_0.12.s390x.rpm SHA-256: 19ac5c9ffd2d282844b33be7854e9b5af01cb40e402865db6066f318436ae4a4
curl-debugsource-7.76.1-14.el9_0.12.s390x.rpm SHA-256: 19ac5c9ffd2d282844b33be7854e9b5af01cb40e402865db6066f318436ae4a4
curl-minimal-7.76.1-14.el9_0.12.s390x.rpm SHA-256: 6f0c8aed55af29ae83548aaa462954516ed0e806fec05dcfa551da4f258acb6a
curl-minimal-debuginfo-7.76.1-14.el9_0.12.s390x.rpm SHA-256: 3e3490d281ae831981b164f52c37ca25d5ff407d74a215686e1c3a5e64394c41
curl-minimal-debuginfo-7.76.1-14.el9_0.12.s390x.rpm SHA-256: 3e3490d281ae831981b164f52c37ca25d5ff407d74a215686e1c3a5e64394c41
libcurl-7.76.1-14.el9_0.12.s390x.rpm SHA-256: 7e7456b85374f936970890cb99224624a720c2e107a51e20ee046ef7562461e6
libcurl-debuginfo-7.76.1-14.el9_0.12.s390x.rpm SHA-256: fc0c249e8e7a82ae6ce5ff11c6c98cba378fc2a756b8bc4ae229b133b1fff818
libcurl-debuginfo-7.76.1-14.el9_0.12.s390x.rpm SHA-256: fc0c249e8e7a82ae6ce5ff11c6c98cba378fc2a756b8bc4ae229b133b1fff818
libcurl-devel-7.76.1-14.el9_0.12.s390x.rpm SHA-256: d951a190d4ab137f86a0201deccf879d9a9bbfa719c6c9c25f40c52246351189
libcurl-minimal-7.76.1-14.el9_0.12.s390x.rpm SHA-256: dd8d5e0e47464dbc06531350bfb4a24a120abbc933c0bbe0cc3a9dee8ca8b960
libcurl-minimal-debuginfo-7.76.1-14.el9_0.12.s390x.rpm SHA-256: 6ab70d62ce6f0f39195f81b8a81c7fd5a7700c4fd9c0c54c61d04bbca1f87a9e
libcurl-minimal-debuginfo-7.76.1-14.el9_0.12.s390x.rpm SHA-256: 6ab70d62ce6f0f39195f81b8a81c7fd5a7700c4fd9c0c54c61d04bbca1f87a9e

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility