IBM Support

Security Bulletin: Multiple vulnerabilities impact AIX due to CURL libcurl (CVE-2026-10536, CVE-2026-11856, CVE-2026-8286, CVE-2026-8458, CVE-2026-8924, CVE-2026-8927, CVE-2026-8932, CVE-2026-9547).

Security Bulletin


Summary

Multiple vulnerabilities in the curl/libcurl are related to use-after-free, reusing an invalid connection, bypass Public Suffix List checks, improper host key validation and invalid authorization.

Vulnerability Details

CVEID:   CVE-2026-10536
DESCRIPTION:   A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.
CWE:   CWE-416: Use After Free
CVSS Source:   CISA ADP
CVSS Base score:   9.8
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-11856
DESCRIPTION:   Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`.
CWE:   CWE-294: Authentication Bypass by Capture-replay
CVSS Source:   CISA ADP
CVSS Base score:   9.8
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-8286
DESCRIPTION:   A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.
CWE:   CWE-295: Improper Certificate Validation
CVSS Source:   CISA ADP
CVSS Base score:   8.1
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)

CVEID:   CVE-2026-8458
DESCRIPTION:   libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.
CVSS Source:   CISA ADP
CVSS Base score:   6.5
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)

CVEID:   CVE-2026-8924
DESCRIPTION:   A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.
CVSS Source:   CISA ADP
CVSS Base score:   9.1
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)

CVEID:   CVE-2026-8927
DESCRIPTION:   When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.
CWE:   CWE-294: Authentication Bypass by Capture-replay
CVSS Source:   CISA ADP
CVSS Base score:   9.1
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)

CVEID:   CVE-2026-8932
DESCRIPTION:   libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.
CVSS Source:   CISA ADP
CVSS Base score:   7.5
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)

CVEID:   CVE-2026-9547
DESCRIPTION:   When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.
CVSS Source:   CISA ADP
CVSS Base score:   7.4
CVSS Vector:   (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)

Affected Products and Versions

Affected Product(s)Version(s)
AIX7.3

 

        The following fileset levels are vulnerable:

 

        key_fileset = aix

 

        Fileset                 Lower Level  Upper Level KEY

        ---------------------------------------------------------

        oss.lib.libcurl         7.79.1.0     7.79.1.0    key_w_fs

        oss.lib.libcurl         8.1.2.0      8.1.2.0     key_w_fs

        oss.lib.libcurl         8.5.0.0      8.5.0.2     key_w_fs

 

        Note: This bulletin does not apply to versions of curl installed from

        the AIX Toolbox.

 

        To find out whether the affected filesets are installed

        on your systems, refer to the lslpp command found in AIX user's guide.

 

        Example:  lslpp -L | grep -i oss.lib.libcurl

Remediation/Fixes

       A. FIXES

 

            IBM strongly recommends addressing the vulnerability now.

 

            AIX fixes are available.

 

            The AIX fixes can be downloaded via https from:

            https://aix.software.ibm.com/aix/efixes/security/curl_fix11.tar

 

            The link above is to a tar file containing this signed

            advisory, fix packages, and OpenSSL signatures for each package.

            The fixes below include prerequisite checking. This will

            enforce the correct mapping between the fixes and AIX

            Technology Levels.

 

            Note that the tar file contains Interim fixes that are based on

            Curl version, and AIX Curl fixes are cumulative.

 

            AIX Level       Interim Fix (*.Z)        KEY

            --------------------------------------------------

            7.3             10536ma.260730.epkg.Z     key_w_fix

 

            Please reference the Affected Products and Version section above

            for help with checking installed fileset levels.

 

            To extract the fixes from the tar file:

 

            tar xvf curl_fix11.tar

            cd curl_fix11

 

            Verify you have retrieved the fixes intact:

 

            The checksums below were generated using the

            "openssl dgst -sha256 [filename]" command as the following:

 

            openssl dgst -sha256                                              filename                 KEY

            -----------------------------------------------------------------------------------------------------

            f48598dcb663bc879bef600b33c8d456fb3f2275cd5790826e0da376b52e4876  10536ma.260730.epkg.Z    key_w_csum

 

            The checksums below were generated using the

            "openssl dgst -sha512 [filename]" command as the following:

 

            openssl dgst -sha512                                                                                                              filename

         KEY

            ---------------------------------------------------------------------------------------------------------------------------------------------------

---------------------

            766433a6b680f316b5bf66d826f3f6b651fb5b9ba940f1dd9c8a861adf207deb68d8579108c57dbcc8561cd9428cea9a45acd7af7fd2da130977006d96bdbb40  10536ma.260730.epkg.Z     key_4K_w_csum

 

 

            These sums should match exactly. The OpenSSL signatures in the tar

            file and on this advisory can also be used to verify the integrityi

            of the fixes.  If the sums or signatures cannot be confirmed, contact

            IBM Support at http://ibm.com/support/ and describe the discrepancy.

 

            openssl dgst -sha256 -verify [pubkey_file] -signature [advisory_file].sig [advisory_file]

 

            openssl dgst -sha256 -verify [pubkey_file] -signature [ifix_file].sig [ifix_file]

 

            Published advisory OpenSSL signature file location:

 

            https://aix.software.ibm.com/aix/efixes/security/curl_advisory11.asc.sig

 

        B. FIX AND INTERIM FIX INSTALLATION

 

            If possible, it is recommended that a mksysb backup of the system

            be created. Verify it is both bootable and readable before

            proceeding.

 

            To preview a fix installation:

 

            installp -a -d fix_name -p all  # where fix_name is the name of the

                                            # fix package being previewed.

            To install a fix package:

 

            installp -a -d fix_name -X all  # where fix_name is the name of the

                                            # fix package being installed.

            Interim fixes have had limited functional and regression

            testing but not the full regression testing that takes place

            for Service Packs; however, IBM does fully support them.

 

            Interim fix management documentation can be found at:

            https://www.ibm.com/support/pages/managing-interim-fixes-aix

 

            To preview an interim fix installation:

 

            emgr -e ipkg_name -p         # where ipkg_name is the name of the

                                         # interim fix package being previewed.

 

            To install an interim fix package:

 

            emgr -e ipkg_name -X         # where ipkg_name is the name of the

                                         # interim fix package being installed.

 

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Acknowledgement

Change History

29 Jul 2026: Initial Publication
Second Issued: Thu Jul 30 07:54:12 CDT 2026 (Fix is updated for dependency on openssl.)

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES ""AS IS"" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY. In addition to other efforts to address potential vulnerabilities, IBM periodically updates the record of components contained in our product offerings. As part of that effort, if IBM identifies previously unidentified packages in a product/service inventory, we address relevant vulnerabilities regardless of CVE date. Inclusion of an older CVEID does not demonstrate that the referenced product has been used by IBM since that date, nor that IBM was aware of a vulnerability as of that date. We are making clients aware of relevant vulnerabilities as we become aware of them. "Affected Products and Versions" referenced in IBM Security Bulletins are intended to be only products and versions that are supported by IBM and have not passed their end-of-support or warranty date. Thus, failure to reference unsupported or extended-support products and versions in this Security Bulletin does not constitute a determination by IBM that they are unaffected by the vulnerability. Reference to one or more unsupported versions in this Security Bulletin shall not create an obligation for IBM to provide fixes for any unsupported or extended-support products or versions.

Document Location

Worldwide

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SWG10","label":"AIX"},"Component":"","Platform":[{"code":"PF002","label":"AIX"}],"Version":"7.3","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}}]

Document Information

Modified date:
30 July 2026

Initial Publish date:
29 July 2026

UID

ibm17281743