When a libcurl-based application performs transfers via SCP:// or SFTP://
and utilizes the CURLOPT_SSH_KEYFUNCTION callback, it may silently accept an
untrusted server. This vulnerability occurs when a server presents a host key
type that does not match the specific key type already recorded for that host
in the known_hosts file. Instead of rejecting the mismatch, the callback
mechanism fails to properly enforce the restriction, allowing the connection
to succeed without warning and risking a potential man-in-the-middle attack.
The product communicates with a host that provides a certificate, but the product does not properly ensure that the certificate is actually associated with that host.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Curl | Haxx | 7.69.0 (including) | 8.21.0 (excluding) |
| Red Hat Enterprise Linux 10 | RedHat | curl-0:8.12.1-4.el10_2.3 | * |
| Red Hat Enterprise Linux 10.0 Extended Update Support | RedHat | curl-0:8.12.1-1.el10_0.10 | * |
| Red Hat Enterprise Linux 9 | RedHat | curl-0:7.76.1-40.el9_8.5 | * |
| Red Hat Enterprise Linux 9 | RedHat | curl-0:7.76.1-40.el9_8.5 | * |
| Red Hat OpenShift Container Platform 4.22 | RedHat | rhcos-4.22.9.8.202608251819-0 | * |
| Red Hat OpenShift Container Platform 4.22 | RedHat | rhcos-4.22.9.8.202609081748-0 | * |
| Cert Manager support for Red Hat OpenShift release 1.19 | RedHat | cert-manager/cert-manager-operator-rhel9:1788348522 | * |
| Cert Manager support for Red Hat OpenShift release 1.19 | RedHat | cert-manager/jetstack-cert-manager-acmesolver-rhel9:1788348571 | * |
| Cert Manager support for Red Hat OpenShift release 1.19 | RedHat | cert-manager/jetstack-cert-manager-rhel9:1788348571 | * |
| Cert Manager support for Red Hat OpenShift release 1.19 | RedHat | cert-manager/cert-manager-istio-csr-rhel9:1788348594 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/jetstack-cert-manager-rhel9:1790223279 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/cert-manager-istio-csr-rhel9:1790223719 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/cert-manager-operator-rhel9:1790272426 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/jetstack-cert-manager-acmesolver-rhel9:1790589998 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/jetstack-cert-manager-rhel9:1790589912 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/cert-manager-istio-csr-rhel9:1790589914 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/cert-manager-operator-rhel9:1790589855 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/cert-manager-trust-manager-rhel9:1790598593 | * |
| Red Hat Discovery 2 | RedHat | discovery/discovery-server-rhel9:1788205779 | * |
| Red Hat Discovery 2 | RedHat | discovery/discovery-ui-rhel9:1788206196 | * |
| Red Hat Hardened Images | RedHat | curl-main-8.21.0-0.1.hum1 | * |
| Red Hat Hardened Images | RedHat | rust-main-1.96.1-1.hum1 | * |
| Red Hat OpenShift Dev Spaces 3.30 | RedHat | devspaces/code-rhel9:1787762793 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/cds-kubernetes-tp-rhel9:1787241211 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/installer-tp-rhel9:1787135742 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/rhua-tp-rhel9:1787241260 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/cds-kubernetes-rhel9:1788880445 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/cds-rhel9:1788880464 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/haproxy-rhel9:1788880456 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/installer-rhel9:1788765051 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/rhua-rhel9:1788880581 | * |
| Curl | Ubuntu | devel | * |
| Curl | Ubuntu | jammy | * |
| Curl | Ubuntu | noble | * |
| Curl | Ubuntu | questing | * |
| Curl | Ubuntu | resolute | * |
| Curl | Ubuntu | upstream | * |
Even if a certificate is well-formed, signed, and follows the chain of trust, it may simply be a valid certificate for a different site than the site that the product is interacting with. In order to ensure data integrity, the certificate must be valid, and it must pertain to the site that is being accessed. Even if the product attempts to check the hostname, it is still possible to incorrectly check the hostname. For example, attackers could create a certificate with a name that begins with a trusted name followed by a NUL byte, which could cause some string-based comparisons to only examine the portion that contains the trusted name.