https://seclists.org/oss-sec/2026/q1/294: [ADVISORY] curl: CVE-2026-3805: use after fe in SMB connection use
Published Mar 11, 2026
·Updated
Affected Software
1 affected component
redhat/libcurl>=8.13.0<=8.18.0
Frequently Asked Questions
1
What is the severity of CVE-2026-3805?
CVE-2026-3805 has been rated as a high severity vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2026-3805?
To fix CVE-2026-3805, update your curl installation to the latest version that addresses this vulnerability.
3
What impact does CVE-2026-3805 have on SMB connections?
CVE-2026-3805 can lead to use-after-free conditions during SMB connection reuse, which may allow an attacker to execute arbitrary code.
4
Which software is affected by CVE-2026-3805?
CVE-2026-3805 affects the curl library, particularly in versions that handle SMB connections.
5
What are the steps to identify CVE-2026-3805 in my environment?
To identify CVE-2026-3805, check your installed curl version and verify if it is vulnerable according to the security advisory.