ALPINE-CVE-2025-0665 PUBLISHED CVSS 7 HIGH

libcurl would wrongly close the same eventfd file descriptor twice when taking down a connection channel after having completed a threaded name resolve.

Risk Scores

CVSS v3.1
7
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H

Affected Products

VendorProductVersions
Alpine:v3.21curl7.65.3-r0, 8.9.1-r2, 8.9.1-r1
Alpine:v3.20curl7.45.0-r0, 8.9.1-r2, 8.9.1-r1
Alpine:v3.23curl8.9.1-r2, 0, 7.19.2-r0
Alpine:v3.18curl7.38.0-r0, 7.37.0-r0, 7.36.0-r0
Alpine:v3.22curl7.41.0-r0, 7.60.0-r1, 8.10.0-r0
Alpine:v3.19curl7.21.1-r0, 7.53.1-r2, 7.29.0-r0

Timeline

References

Open in Interactive Console →