CVE-2026-3805

medium Red Hat
CVSS v3 Base Score
6.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
EPSS Score
0.0%
Exploitation probability in 30 days
Top 89% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Confidentiality
Low
Integrity
Low
Availability
Low
Published: March 11, 2026 (64 days ago)
Last Modified: March 11, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in curl. When handling a second Server Message Block (SMB) request to the same host, curl incorrectly accesses memory that has already been freed. This memory corruption vulnerability, known as a use-after-free, could allow a remote attacker to potentially execute arbitrary code or cause a denial of service.

CWE

CWE-825

Affected Products

Confidential Compute AttestationLogging Subsystem for Red Hat OpenShiftRed Hat Enterprise Linux 10Red Hat Enterprise Linux 6Red Hat Enterprise Linux 7Red Hat Enterprise Linux 8Red Hat Enterprise Linux 9Red Hat Enterprise Linux AI (RHEL AI) 3Red Hat JBoss Core ServicesRed Hat OpenShift Container Platform 4

References