CVE-2025-0665: eventfd double close
eventfd double close
Other sources
libcurl would wrongly close the same eventfd file descriptor twice when taking down a connection channel after having completed a threaded name resolve.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.11.1-3
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0665?
CVE-2025-0665 has a severity rating that indicates a potential risk of resource leaks and crashes in libcurl.
How do I fix CVE-2025-0665?
To fix CVE-2025-0665, you should upgrade to the latest version of libcurl that addresses this vulnerability.
What impact does CVE-2025-0665 have on applications using libcurl?
CVE-2025-0665 can lead to application instability due to improper handling of file descriptors, possibly causing crashes.
Which versions of libcurl are affected by CVE-2025-0665?
CVE-2025-0665 affects certain versions of libcurl prior to the patch that resolves this specific issue.
Is CVE-2025-0665 a remote code execution vulnerability?
No, CVE-2025-0665 is not classified as a remote code execution vulnerability but rather involves resource management issues.