Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:23383 - Security Advisory
Issued:
2025-12-16
Updated:
2025-12-18

RHSA-2025:23383 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: curl security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for curl is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.

Security Fix(es):

  • curl: libcurl: Curl out of bounds read for cookie path (CVE-2025-9086)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64

Fixes

  • BZ - 2394750 - CVE-2025-9086 curl: libcurl: Curl out of bounds read for cookie path

CVEs

  • CVE-2025-9086

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
curl-7.61.1-34.el8_10.9.src.rpm SHA-256: b69dcfee680f356433e48929a3b447b72d6e99bf8ad61b5a6c9ac2eededf87cd
x86_64
curl-7.61.1-34.el8_10.9.x86_64.rpm SHA-256: 80a15ee8d048cc81629020d2ad8c4037e63eb6c8d06017c7e8b2109751e7425d
curl-debuginfo-7.61.1-34.el8_10.9.i686.rpm SHA-256: ef8dfcec35522b593240af833ee77f99a7e8c501669b574c674f0836970fae1a
curl-debuginfo-7.61.1-34.el8_10.9.x86_64.rpm SHA-256: bcb8d6d0ce7acb4ba6d5747e19e5e0cba1bddc6fc14cdb399e10efb0b46852c9
curl-debugsource-7.61.1-34.el8_10.9.i686.rpm SHA-256: 0708d1feaf2fb1748223c3d71147bfae65f55e89c8722cf79ab695e77ffc931b
curl-debugsource-7.61.1-34.el8_10.9.x86_64.rpm SHA-256: debd9e9897ed9c2ea5fe6f541bd37c5c01fbd33fb66ae5f4aaa1c789d3419955
curl-minimal-debuginfo-7.61.1-34.el8_10.9.i686.rpm SHA-256: c8e8bbcacd5140faf909000861265afe40caae1f0cdc090da9c01bd38968cf4e
curl-minimal-debuginfo-7.61.1-34.el8_10.9.x86_64.rpm SHA-256: 9a47b5c7511ec88b507418926ee622c188b21c34d29520679ea84d2826a4322f
libcurl-7.61.1-34.el8_10.9.i686.rpm SHA-256: 74fb563bf769cb897359ee5cbc2db3fd0c8e263a6e0503a22d4370cf61133a0c
libcurl-7.61.1-34.el8_10.9.x86_64.rpm SHA-256: 7afd52dae8ea3545897e5d83e47668472a5434200f696ee7755be6a4ecf96608
libcurl-debuginfo-7.61.1-34.el8_10.9.i686.rpm SHA-256: 8aea2e4590549ff63adb18f0ac80ae1af377de7adca27bea1a8d3ce5e6089c5f
libcurl-debuginfo-7.61.1-34.el8_10.9.x86_64.rpm SHA-256: 3dbfba1eb3d4da240b5523f934fbd186021e0f6546a0b34938ca6d6b36dbaea7
libcurl-devel-7.61.1-34.el8_10.9.i686.rpm SHA-256: bf21ab814de133ae0a59c82c4bf48159878d02242b54b87a91b98cefff9c0242
libcurl-devel-7.61.1-34.el8_10.9.x86_64.rpm SHA-256: 26bd79e082d96a0405e8927d7e758de399232ba31ab337c13fe64a7f461159b4
libcurl-minimal-7.61.1-34.el8_10.9.i686.rpm SHA-256: aa81c1c42e27fa548db04b068e1faa2bfe1c69085c4cce245b90ec9677b24914
libcurl-minimal-7.61.1-34.el8_10.9.x86_64.rpm SHA-256: 014e3217328824c9f9d0e18e3f9926db557f32128e2c7824128174be9c02079f
libcurl-minimal-debuginfo-7.61.1-34.el8_10.9.i686.rpm SHA-256: f7492216cb598e30a0bb966dc3e776af2c787bc7401d8a143dd8b1c02634b491
libcurl-minimal-debuginfo-7.61.1-34.el8_10.9.x86_64.rpm SHA-256: aa670ffbbd3632bfe5295aa923240758c636121a64ccf001875be85918a992d9

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
curl-7.61.1-34.el8_10.9.src.rpm SHA-256: b69dcfee680f356433e48929a3b447b72d6e99bf8ad61b5a6c9ac2eededf87cd
s390x
curl-7.61.1-34.el8_10.9.s390x.rpm SHA-256: deb89d87cdc83b3ed7c9206c5f3b6a148c6e0de82eaa7bff235d7838910e176c
curl-debuginfo-7.61.1-34.el8_10.9.s390x.rpm SHA-256: 5582da544d7b4e1a6f6dd22e1298ca78296c113b26d738ad36f2b60d23ae4ca4
curl-debugsource-7.61.1-34.el8_10.9.s390x.rpm SHA-256: 3a9fda0449cffddbb30e618aa3b98998065088d4123d19c8248d4d0e1ecc9cfc
curl-minimal-debuginfo-7.61.1-34.el8_10.9.s390x.rpm SHA-256: e8ef341feb175aab1af2e32a256154c0c8e731a2d05d69b0aa1d92c295d6606e
libcurl-7.61.1-34.el8_10.9.s390x.rpm SHA-256: 46d9a691c61bce34ce30e39ae3bb9fb7ca744dbc0c8fc2fe01522ab79aca1867
libcurl-debuginfo-7.61.1-34.el8_10.9.s390x.rpm SHA-256: d50909c3642423dbe1a28440838ea3f68e4405c1331e529fbf75e5eb5d816380
libcurl-devel-7.61.1-34.el8_10.9.s390x.rpm SHA-256: 78defcc11f99212a78c166ffe74b085ff40ab54172ddacc14adbdc0ebdd7bb15
libcurl-minimal-7.61.1-34.el8_10.9.s390x.rpm SHA-256: 41f97d0cb389af43135667188ef879579dfff572d165c272e91eba8147e53cd5
libcurl-minimal-debuginfo-7.61.1-34.el8_10.9.s390x.rpm SHA-256: 140b1405da8ef5d1023c8e3194ae59a041839b7bd2d5095fdb35f80a8a6adbf5

Red Hat Enterprise Linux for Power, little endian 8

SRPM
curl-7.61.1-34.el8_10.9.src.rpm SHA-256: b69dcfee680f356433e48929a3b447b72d6e99bf8ad61b5a6c9ac2eededf87cd
ppc64le
curl-7.61.1-34.el8_10.9.ppc64le.rpm SHA-256: 099c46e57263838ec3a35d6ecb017ca3ded6054dfa2f189b22e410e8899ea5b7
curl-debuginfo-7.61.1-34.el8_10.9.ppc64le.rpm SHA-256: db843f2f0608c13d111e74fbbb99c50be3e2c9523b3f80cc3649985247258ef7
curl-debugsource-7.61.1-34.el8_10.9.ppc64le.rpm SHA-256: 06b470e2b02dbe906a032041c154ac34099e80cbfbcdfbdc6cf4d06f7284f3c1
curl-minimal-debuginfo-7.61.1-34.el8_10.9.ppc64le.rpm SHA-256: 0e5f30e0c7005bb068cd64644140545e2a41a5c45b206fe4cd653ea276e38eb1
libcurl-7.61.1-34.el8_10.9.ppc64le.rpm SHA-256: 18cff1828997288bf377355316b7e81d91e21dd01bb37d4888aefa1a3ac83a68
libcurl-debuginfo-7.61.1-34.el8_10.9.ppc64le.rpm SHA-256: 2130dbef7555dbc10bf5e4aadd927f49db8f96c86c3a0df564c8986d65f67681
libcurl-devel-7.61.1-34.el8_10.9.ppc64le.rpm SHA-256: 96a4a391a0b1a7ec359f48d669083c4826ecf476522029e36d2f60def8336164
libcurl-minimal-7.61.1-34.el8_10.9.ppc64le.rpm SHA-256: 3eb8d9d1c48013153dc18e898684bf756ee12fd4d7a023717e4532bb04c2977b
libcurl-minimal-debuginfo-7.61.1-34.el8_10.9.ppc64le.rpm SHA-256: cee8cc57d176ad65143433562ce309a0306aaf6b7f94bc65a5636b9dae54727f

Red Hat Enterprise Linux for ARM 64 8

SRPM
curl-7.61.1-34.el8_10.9.src.rpm SHA-256: b69dcfee680f356433e48929a3b447b72d6e99bf8ad61b5a6c9ac2eededf87cd
aarch64
curl-7.61.1-34.el8_10.9.aarch64.rpm SHA-256: eb6b2b9bbe7f5eeec0d259c59995303c7e266dbf6e6e4f20ceca13427dfaf2a6
curl-debuginfo-7.61.1-34.el8_10.9.aarch64.rpm SHA-256: 80edb5eb305565254ad922eb24fd92d3edbc71ab7fbd68028179945011f6da5c
curl-debugsource-7.61.1-34.el8_10.9.aarch64.rpm SHA-256: 858c0b8c37496949b9e8f6857e5bac0c2dad0e530965c5d7e832ba6f59af80f2
curl-minimal-debuginfo-7.61.1-34.el8_10.9.aarch64.rpm SHA-256: 62d7f68effc39dc93ff6167a7971f36c7953b77d6f07b1ddae82783992a47a3c
libcurl-7.61.1-34.el8_10.9.aarch64.rpm SHA-256: 855a2115646f802403e292094874fce962680a4432426d63b0179152815c1b9e
libcurl-debuginfo-7.61.1-34.el8_10.9.aarch64.rpm SHA-256: cd1be170779de87f17c4afe08a646658889ec1481082f453f846580268c67183
libcurl-devel-7.61.1-34.el8_10.9.aarch64.rpm SHA-256: 59d9c69971a0f45874ef65b6f905af479dd87b7675f2e3b870606bcbf3eba19f
libcurl-minimal-7.61.1-34.el8_10.9.aarch64.rpm SHA-256: e3671e5585069fa1faeb74aae49a17599859fea4cf540a5da9e22d4e610049df
libcurl-minimal-debuginfo-7.61.1-34.el8_10.9.aarch64.rpm SHA-256: 0949a76176b5a6ac4fdf75e560b7e64465e358065ea6ad57b46db65a2385e4d2

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility