{"id":"DEBIAN-CVE-2026-18924","details":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.","modified":"2026-09-19T05:00:09.452847496Z","published":"2026-09-06T18:17:20.553Z","upstream":["CVE-2026-18924"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-18924"}],"affected":[{"package":{"name":"curl","ecosystem":"Debian:12","purl":"pkg:deb/debian/curl?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.88.1-10","7.88.1-10+deb12u1","7.88.1-10+deb12u11","7.88.1-10+deb12u12","7.88.1-10+deb12u13","7.88.1-10+deb12u14","7.88.1-10+deb12u15","7.88.1-10+deb12u1~bpo11+1","7.88.1-10+deb12u2","7.88.1-10+deb12u3","7.88.1-10+deb12u3~bpo11+1","7.88.1-10+deb12u4","7.88.1-10+deb12u5","7.88.1-10+deb12u5~bpo11+1","7.88.1-10+deb12u6","7.88.1-10+deb12u6~bpo11+1","7.88.1-10+deb12u7","7.88.1-10+deb12u8","7.88.1-10+deb12u9","7.88.1-11","8.0.1-1~exp1","8.10.0-1","8.10.0-2","8.10.1-1","8.10.1-1~bpo12+1","8.10.1-2","8.11.0-1","8.11.1-1","8.11.1-1~bpo12+1","8.12.0+git20250209.89ed161+ds-1","8.12.0+git20250209.89ed161+ds-1~bpo12+1","8.12.1-1","8.12.1-2","8.12.1-2~bpo12+1","8.12.1-3","8.12.1-3~bpo12+1","8.13.0-1","8.13.0-1+exp1","8.13.0-2","8.13.0-2+exp1","8.13.0-3","8.13.0-4","8.13.0-4+exp1","8.13.0-5","8.13.0-5+exp1","8.13.0-5~bpo12+1","8.13.0~rc-1~exp1","8.13.0~rc-1~exp2","8.13.0~rc2-1","8.13.0~rc2-2","8.13.0~rc3-1","8.13.0~rc3-1+exp1","8.14.0-1","8.14.0-1+exp1","8.14.0~rc1-1+exp1","8.14.0~rc2-1+exp1","8.14.0~rc3-1+exp1","8.14.1-1","8.14.1-1~bpo12+1","8.14.1-2","8.14.1-2+exp1","8.14.1-2~bpo12+1","8.15.0-1","8.15.0-1~bpo13+1","8.15.0-1~exp1","8.15.0~rc1-1exp1","8.15.0~rc2-1~exp1","8.15.0~rc3-1~exp1","8.16.0-1","8.16.0-1+exp1","8.16.0-1~bpo13+1","8.16.0-2","8.16.0-3","8.16.0-4","8.16.0-4~bpo13+1","8.16.0~rc1-1~exp1","8.16.0~rc2-1","8.16.0~rc2-2","8.16.0~rc3-1","8.17.0-1","8.17.0-2","8.17.0-3","8.17.0~rc1-1~exp1","8.17.0~rc2-1","8.17.0~rc3-1","8.18.0-1","8.18.0-1~bpo13+1","8.18.0-2","8.18.0~rc1-1+exp1","8.18.0~rc2-1","8.18.0~rc3-1","8.19.0-1","8.19.0-1+exp1","8.19.0-1~bpo13+1","8.19.0-2","8.19.0-3","8.19.0-3+exp1","8.19.0-3+exp2","8.19.0~rc1-1~exp1","8.19.0~rc2-1","8.19.0~rc2-2","8.19.0~rc3-1","8.2.1-1","8.2.1-2","8.2.1-2~bpo12+1","8.20.0-1","8.20.0-1+exp","8.20.0-2","8.20.0-2+exp1","8.20.0-2~bpo13+1","8.20.0-3","8.20.0-4","8.20.0-5","8.20.0-5~bpo13+1","8.20.0~rc1-1+exp1","8.20.0~rc1-1+exp2","8.20.0~rc1-1+exp3","8.20.0~rc2-1","8.20.0~rc2-1+exp1","8.20.0~rc3-1","8.20.0~rc3-1+exp1","8.21.0-1","8.21.0-1+exp1","8.21.0-2","8.21.0-2+exp1","8.21.0-2~bpo13+1","8.21.0~rc1-1+exp1","8.21.0~rc2-1","8.21.0~rc2-1+exp1","8.21.0~rc3-1","8.21.0~rc3-1+exp1","8.22.0-1","8.22.0-1+exp1","8.22.0~rc2-1","8.22.0~rc2-2","8.22.0~rc3-1","8.22.0~rc3-1+exp1","8.3.0-1","8.3.0-2","8.3.0-2~bpo12+1","8.3.0-2~exp1","8.3.0-3","8.4.0-1","8.4.0-2","8.4.0-2~bpo12+1","8.5.0-1","8.5.0-1+exp1","8.5.0-2","8.5.0-2+exp1","8.5.0-2~bpo12+1","8.6.0-1","8.6.0-1.1","8.6.0-2","8.6.0-3","8.6.0-3.1","8.6.0-3.1~exp1","8.6.0-3.1~exp2","8.6.0-3.2","8.6.0-4","8.7.1-1","8.7.1-1+exp1","8.7.1-2","8.7.1-3","8.7.1-4","8.7.1-5","8.7.1-5+exp1","8.7.1-5~bpo12+1","8.8.0-1","8.8.0-1+exp1","8.8.0-1+exp2","8.8.0-1~bpo12+1","8.8.0-2","8.8.0-3","8.8.0-4","8.9.0-1","8.9.0-2","8.9.0-3","8.9.1-1","8.9.1-2","8.9.1-2~bpo12+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-18924.json"}},{"package":{"name":"curl","ecosystem":"Debian:13","purl":"pkg:deb/debian/curl?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["8.14.1-2","8.14.1-2+deb13u1","8.14.1-2+deb13u2","8.14.1-2+deb13u2~bpo13+1","8.14.1-2+deb13u3","8.14.1-2+deb13u4","8.14.1-2+deb13u5","8.14.1-2+exp1","8.15.0-1","8.15.0-1~bpo13+1","8.15.0-1~exp1","8.15.0~rc1-1exp1","8.15.0~rc2-1~exp1","8.15.0~rc3-1~exp1","8.16.0-1","8.16.0-1+exp1","8.16.0-1~bpo13+1","8.16.0-2","8.16.0-3","8.16.0-4","8.16.0-4~bpo13+1","8.16.0~rc1-1~exp1","8.16.0~rc2-1","8.16.0~rc2-2","8.16.0~rc3-1","8.17.0-1","8.17.0-2","8.17.0-3","8.17.0~rc1-1~exp1","8.17.0~rc2-1","8.17.0~rc3-1","8.18.0-1","8.18.0-1~bpo13+1","8.18.0-2","8.18.0~rc1-1+exp1","8.18.0~rc2-1","8.18.0~rc3-1","8.19.0-1","8.19.0-1+exp1","8.19.0-1~bpo13+1","8.19.0-2","8.19.0-3","8.19.0-3+exp1","8.19.0-3+exp2","8.19.0~rc1-1~exp1","8.19.0~rc2-1","8.19.0~rc2-2","8.19.0~rc3-1","8.20.0-1","8.20.0-1+exp","8.20.0-2","8.20.0-2+exp1","8.20.0-2~bpo13+1","8.20.0-3","8.20.0-4","8.20.0-5","8.20.0-5~bpo13+1","8.20.0~rc1-1+exp1","8.20.0~rc1-1+exp2","8.20.0~rc1-1+exp3","8.20.0~rc2-1","8.20.0~rc2-1+exp1","8.20.0~rc3-1","8.20.0~rc3-1+exp1","8.21.0-1","8.21.0-1+exp1","8.21.0-2","8.21.0-2+exp1","8.21.0-2~bpo13+1","8.21.0~rc1-1+exp1","8.21.0~rc2-1","8.21.0~rc2-1+exp1","8.21.0~rc3-1","8.21.0~rc3-1+exp1","8.22.0-1","8.22.0-1+exp1","8.22.0~rc2-1","8.22.0~rc2-2","8.22.0~rc3-1","8.22.0~rc3-1+exp1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-18924.json"}},{"package":{"name":"curl","ecosystem":"Debian:14","purl":"pkg:deb/debian/curl?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.22.0~rc2-1"}]}],"versions":["8.14.1-2","8.14.1-2+exp1","8.15.0-1","8.15.0-1~bpo13+1","8.15.0-1~exp1","8.15.0~rc1-1exp1","8.15.0~rc2-1~exp1","8.15.0~rc3-1~exp1","8.16.0-1","8.16.0-1+exp1","8.16.0-1~bpo13+1","8.16.0-2","8.16.0-3","8.16.0-4","8.16.0-4~bpo13+1","8.16.0~rc1-1~exp1","8.16.0~rc2-1","8.16.0~rc2-2","8.16.0~rc3-1","8.17.0-1","8.17.0-2","8.17.0-3","8.17.0~rc1-1~exp1","8.17.0~rc2-1","8.17.0~rc3-1","8.18.0-1","8.18.0-1~bpo13+1","8.18.0-2","8.18.0~rc1-1+exp1","8.18.0~rc2-1","8.18.0~rc3-1","8.19.0-1","8.19.0-1+exp1","8.19.0-1~bpo13+1","8.19.0-2","8.19.0-3","8.19.0-3+exp1","8.19.0-3+exp2","8.19.0~rc1-1~exp1","8.19.0~rc2-1","8.19.0~rc2-2","8.19.0~rc3-1","8.20.0-1","8.20.0-1+exp","8.20.0-2","8.20.0-2+exp1","8.20.0-2~bpo13+1","8.20.0-3","8.20.0-4","8.20.0-5","8.20.0-5~bpo13+1","8.20.0~rc1-1+exp1","8.20.0~rc1-1+exp2","8.20.0~rc1-1+exp3","8.20.0~rc2-1","8.20.0~rc2-1+exp1","8.20.0~rc3-1","8.20.0~rc3-1+exp1","8.21.0-1","8.21.0-1+exp1","8.21.0-2","8.21.0-2+exp1","8.21.0-2~bpo13+1","8.21.0~rc1-1+exp1","8.21.0~rc2-1","8.21.0~rc2-1+exp1","8.21.0~rc3-1","8.21.0~rc3-1+exp1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-18924.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"}]}