vulnerability

Red Hat: CVE-2022-27775: CVE-2022-27775 curl: bad local IPv6 connection reuse (Multiple Advisories)

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Jun 2, 2022
Added
Nov 16, 2022
Modified
Mar 27, 2026

Description

An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.

Solutions

redhat-upgrade-curlredhat-upgrade-curl-debuginforedhat-upgrade-curl-debugsourceredhat-upgrade-curl-minimalredhat-upgrade-curl-minimal-debuginforedhat-upgrade-libcurlredhat-upgrade-libcurl-debuginforedhat-upgrade-libcurl-develredhat-upgrade-libcurl-minimalredhat-upgrade-libcurl-minimal-debuginfo
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.