← Back to blog

Ubuntu Patches Incomplete Fix in curl, Releasing USN-8487-2

An incomplete patch for curl's STARTTLS connection reuse flaw led to a follow-up update. The vulnerability could allow attackers to bypass intended TLS configurations.

TL;DR

  • Ubuntu released USN-8487-2 to correct an incomplete fix in curl’s previous update.
  • The flaw relates to improper connection reuse during STARTTLS upgrades with mismatched TLS settings.
  • Additional vulnerabilities included issues with Negotiate authentication and cookie parsing.
  • Affects multiple Ubuntu LTS versions including 18.04, 20.04, 22.04, and newer releases.
  • Users should update curl immediately to prevent potential credential and data exposure.

Ubuntu has issued a new security update, USN-8487-2, to resolve a regression in the widely used curl utility. The initial fix, released under USN-8487-1, failed to fully address CVE-2026-8927, prompting this follow-up correction.

This flaw, among others, poses significant risk to secure communications and authentication workflows. Organizations using curl in automated systems or API integrations should prioritize applying this patch to mitigate potential exploitation.

Flaw Details and Risks

  • CVE-2026-8286 allows curl to reuse a live connection during STARTTLS upgrades even when TLS settings don't match, potentially enabling attackers to bypass encryption.
  • CVE-2026-8458 affects Negotiate-authenticated requests, allowing unauthorized access across services on older Ubuntu LTS versions.
  • Cookie parsing issues (affecting Ubuntu 16.04 through 24.04) may lead to cross-domain cookie leakage, increasing tracking and CSRF risks.

Affected Systems and Recommendations

  • Impacted Ubuntu versions include 18.04 LTS, 20.04 LTS, 22.04 LTS, 24.04 LTS, 25.10, and 26.04 LTS.
  • Administrators should upgrade curl via apt or their system’s package manager immediately.
  • Review any applications relying on curl for secure communication to ensure they enforce expected TLS behavior post-patch.
  • Monitor logs for unusual authentication patterns or unexpected cookie behaviors following remediation.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.