VDB
BDU%3A2025-12599
BDU%3A2025-12599
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость утилиты командной строки cURL, связанная с чтением данных за границами буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Novell Inc., ООО «Ред Софт», ООО «РусБИТех-Астра», Daniel Stenberg | Red Hat Enterprise Linux, openSUSE Tumbleweed, РЕД ОС (запись в едином реестре российских программ №3751), Astra Linux Special Edition (запись в едином реестре российских программ №369), SUSE Linux Enterprise Server for SAP Applications, SUSE Linux Enterprise Micro, Suse Linux Enterprise Server, Suse Linux Enterprise Desktop, SUSE Manager Retail Branch Server, SUSE Manager Proxy, SUSE Manager Server, SUSE Linux Enterprise High Performance Computing, SUSE Enterprise Storage, OpenSUSE Leap, cURL, SUSE Linux Enterprise Installer Updates |
Timeline
- Oct 8, 2025 CVE Published
- Feb 16, 2026 CVE Updated
References
- https://curl.se/docs/CVE-2025-9086.json url
- https://curl.se/docs/CVE-2025-9086.html url
- https://redos.red-soft.ru/support/secure/uyazvimosti/uyazvimost-curl-cve-2025-9086/?sphrase_id=1314102 url
- https://www.suse.com/ko-kr/security/cve/CVE-2025-9086.html url
- https://wiki.astralinux.ru/astra-linux-se18-bulletin-2025-1113SE18 url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2025-1202SE17 advisory
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-1216SE47 advisory
- https://access.redhat.com/security/cve/cve-2025-9086 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-1216SE351 url
- https://hackerone.com/reports/3294999 url
- https://wiki.astralinux.ru/astra-linux-se38-bulletin-2026-0126SE38 url