<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for curl</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2025:03267-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2025-09-18T11:06:28Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2025-09-18T11:06:28Z</InitialReleaseDate>
    <CurrentReleaseDate>2025-09-18T11:06:28Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for curl</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for curl fixes the following issues:

Security issues fixed:

- CVE-2025-9086: bug in patch comparison logic when processing cookies can lead to out-of-bounds read in heap buffer
  (bsc#1249191).
- CVE-2025-10148: predictable websocket mask can lead to proxy cache poisoning by malicious server (bsc#1249348).
    
Other issues fixed:
    
- Fix the --ftp-pasv option in curl v8.14.1 (bsc#1246197).
  * tool_getparam: fix --ftp-pasv [5f805ee]

- Update to version 8.14.1 (jsc#PED-13055, jsc#PED-13056).
  * TLS: add CURLOPT_SSL_SIGNATURE_ALGORITHMS and --sigalgs.
  * websocket: add option to disable auto-pong reply.
  * huge number of bugfixes.

  Please see https://curl.se/ch/ for full changelogs.
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">Container suse/manager/4.3/proxy-httpd:latest-2025-3267,Container suse/manager/4.3/proxy-salt-broker:latest-2025-3267,Container suse/sle-micro-rancher/5.3:latest-2025-3267,Container suse/sle-micro-rancher/5.4:latest-2025-3267,Container suse/sle-micro/5.5:latest-2025-3267,Container suse/sle-micro/base-5.5:latest-2025-3267,Container suse/sle-micro/kvm-5.5:latest-2025-3267,Container suse/sle-micro/rt-5.5:latest-2025-3267,SUSE-2025-3267,SUSE-SLE-INSTALLER-15-SP4-2025-3267,SUSE-SLE-INSTALLER-15-SP5-2025-3267,SUSE-SLE-Micro-5.3-2025-3267,SUSE-SLE-Micro-5.4-2025-3267,SUSE-SLE-Micro-5.5-2025-3267,SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-3267,SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-3267,SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-3267,SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-3267,SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-3267,SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-3267,SUSE-SLE-Product-SLES_SAP-15-SP4-2025-3267,SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-LTS-2025-3267,SUSE-SLE-Product-SUSE-Manager-Server-4.3-LTS-2025-3267</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2025/suse-su-202503267-1/</URL>
      <Description>Link for SUSE-SU-2025:03267-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-updates/2025-September/041770.html</URL>
      <Description>E-Mail link for SUSE-SU-2025:03267-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1246197</URL>
      <Description>SUSE Bug 1246197</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1249191</URL>
      <Description>SUSE Bug 1249191</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1249348</URL>
      <Description>SUSE Bug 1249348</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1249367</URL>
      <Description>SUSE Bug 1249367</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2025-10148/</URL>
      <Description>SUSE CVE CVE-2025-10148 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2025-9086/</URL>
      <Description>SUSE CVE CVE-2025-9086 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="Container suse/manager/4.3/proxy-httpd:latest">
      <Branch Type="Product Name" Name="Container suse/manager/4.3/proxy-httpd:latest">
        <FullProductName ProductID="Container suse/manager/4.3/proxy-httpd:latest">Container suse/manager/4.3/proxy-httpd:latest</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Container suse/manager/4.3/proxy-salt-broker:latest">
      <Branch Type="Product Name" Name="Container suse/manager/4.3/proxy-salt-broker:latest">
        <FullProductName ProductID="Container suse/manager/4.3/proxy-salt-broker:latest">Container suse/manager/4.3/proxy-salt-broker:latest</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Container suse/sle-micro-rancher/5.3:latest">
      <Branch Type="Product Name" Name="Container suse/sle-micro-rancher/5.3:latest">
        <FullProductName ProductID="Container suse/sle-micro-rancher/5.3:latest">Container suse/sle-micro-rancher/5.3:latest</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Container suse/sle-micro-rancher/5.4:latest">
      <Branch Type="Product Name" Name="Container suse/sle-micro-rancher/5.4:latest">
        <FullProductName ProductID="Container suse/sle-micro-rancher/5.4:latest">Container suse/sle-micro-rancher/5.4:latest</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Container suse/sle-micro/5.5:latest">
      <Branch Type="Product Name" Name="Container suse/sle-micro/5.5:latest">
        <FullProductName ProductID="Container suse/sle-micro/5.5:latest">Container suse/sle-micro/5.5:latest</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Container suse/sle-micro/base-5.5:latest">
      <Branch Type="Product Name" Name="Container suse/sle-micro/base-5.5:latest">
        <FullProductName ProductID="Container suse/sle-micro/base-5.5:latest">Container suse/sle-micro/base-5.5:latest</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Container suse/sle-micro/kvm-5.5:latest">
      <Branch Type="Product Name" Name="Container suse/sle-micro/kvm-5.5:latest">
        <FullProductName ProductID="Container suse/sle-micro/kvm-5.5:latest">Container suse/sle-micro/kvm-5.5:latest</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Container suse/sle-micro/rt-5.5:latest">
      <Branch Type="Product Name" Name="Container suse/sle-micro/rt-5.5:latest">
        <FullProductName ProductID="Container suse/sle-micro/rt-5.5:latest">Container suse/sle-micro/rt-5.5:latest</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS">
        <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS" CPE="cpe:/o:suse:sle_hpc-espos:15:sp4">SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS" CPE="cpe:/o:suse:sle_hpc-ltss:15:sp4">SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS">
        <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS" CPE="cpe:/o:suse:sle_hpc-espos:15:sp5">SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS" CPE="cpe:/o:suse:sle_hpc-ltss:15:sp5">SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Installer Updates 15 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Installer Updates 15 SP4">
        <FullProductName ProductID="SUSE Linux Enterprise Installer Updates 15 SP4">SUSE Linux Enterprise Installer Updates 15 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Installer Updates 15 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Installer Updates 15 SP5">
        <FullProductName ProductID="SUSE Linux Enterprise Installer Updates 15 SP5">SUSE Linux Enterprise Installer Updates 15 SP5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Micro 5.3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Micro 5.3">
        <FullProductName ProductID="SUSE Linux Enterprise Micro 5.3" CPE="cpe:/o:suse:sle-micro:5.3">SUSE Linux Enterprise Micro 5.3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Micro 5.4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Micro 5.4">
        <FullProductName ProductID="SUSE Linux Enterprise Micro 5.4" CPE="cpe:/o:suse:sle-micro:5.4">SUSE Linux Enterprise Micro 5.4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Micro 5.5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Micro 5.5">
        <FullProductName ProductID="SUSE Linux Enterprise Micro 5.5" CPE="cpe:/o:suse:sle-micro:5.5">SUSE Linux Enterprise Micro 5.5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 15 SP4-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 15 SP4-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP4-LTSS" CPE="cpe:/o:suse:sles-ltss:15:sp4">SUSE Linux Enterprise Server 15 SP4-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 15 SP5-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 15 SP5-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP5-LTSS" CPE="cpe:/o:suse:sles-ltss:15:sp5">SUSE Linux Enterprise Server 15 SP5-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP4">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP4" CPE="cpe:/o:suse:sles_sap:15:sp4">SUSE Linux Enterprise Server for SAP Applications 15 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Proxy LTS 4.3">
      <Branch Type="Product Name" Name="SUSE Manager Proxy LTS 4.3">
        <FullProductName ProductID="SUSE Manager Proxy LTS 4.3" CPE="cpe:/o:suse:suse-manager-proxy-lts:4.3">SUSE Manager Proxy LTS 4.3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Server LTS 4.3">
      <Branch Type="Product Name" Name="SUSE Manager Server LTS 4.3">
        <FullProductName ProductID="SUSE Manager Server LTS 4.3" CPE="cpe:/o:suse:suse-manager-server-lts:4.3">SUSE Manager Server LTS 4.3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="curl-8.14.1-150400.5.69.1">
      <FullProductName ProductID="curl-8.14.1-150400.5.69.1">curl-8.14.1-150400.5.69.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcurl4-8.14.1-150400.5.69.1">
      <FullProductName ProductID="libcurl4-8.14.1-150400.5.69.1">libcurl4-8.14.1-150400.5.69.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="curl-fish-completion-8.14.1-150400.5.69.1">
      <FullProductName ProductID="curl-fish-completion-8.14.1-150400.5.69.1">curl-fish-completion-8.14.1-150400.5.69.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="curl-zsh-completion-8.14.1-150400.5.69.1">
      <FullProductName ProductID="curl-zsh-completion-8.14.1-150400.5.69.1">curl-zsh-completion-8.14.1-150400.5.69.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcurl-devel-8.14.1-150400.5.69.1">
      <FullProductName ProductID="libcurl-devel-8.14.1-150400.5.69.1">libcurl-devel-8.14.1-150400.5.69.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcurl-devel-32bit-8.14.1-150400.5.69.1">
      <FullProductName ProductID="libcurl-devel-32bit-8.14.1-150400.5.69.1">libcurl-devel-32bit-8.14.1-150400.5.69.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcurl-devel-64bit-8.14.1-150400.5.69.1">
      <FullProductName ProductID="libcurl-devel-64bit-8.14.1-150400.5.69.1">libcurl-devel-64bit-8.14.1-150400.5.69.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcurl-devel-doc-8.14.1-150400.5.69.1">
      <FullProductName ProductID="libcurl-devel-doc-8.14.1-150400.5.69.1">libcurl-devel-doc-8.14.1-150400.5.69.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcurl-mini4-8.14.1-150400.5.69.1">
      <FullProductName ProductID="libcurl-mini4-8.14.1-150400.5.69.1">libcurl-mini4-8.14.1-150400.5.69.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcurl4-32bit-8.14.1-150400.5.69.1">
      <FullProductName ProductID="libcurl4-32bit-8.14.1-150400.5.69.1">libcurl4-32bit-8.14.1-150400.5.69.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcurl4-64bit-8.14.1-150400.5.69.1">
      <FullProductName ProductID="libcurl4-64bit-8.14.1-150400.5.69.1">libcurl4-64bit-8.14.1-150400.5.69.1</FullProductName>
    </Branch>
    <Relationship ProductReference="curl-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/manager/4.3/proxy-httpd:latest">
      <FullProductName ProductID="Container suse/manager/4.3/proxy-httpd:latest:curl-8.14.1-150400.5.69.1">curl-8.14.1-150400.5.69.1 as a component of Container suse/manager/4.3/proxy-httpd:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/manager/4.3/proxy-httpd:latest">
      <FullProductName ProductID="Container suse/manager/4.3/proxy-httpd:latest:libcurl4-8.14.1-150400.5.69.1">libcurl4-8.14.1-150400.5.69.1 as a component of Container suse/manager/4.3/proxy-httpd:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/manager/4.3/proxy-salt-broker:latest">
      <FullProductName ProductID="Container suse/manager/4.3/proxy-salt-broker:latest:curl-8.14.1-150400.5.69.1">curl-8.14.1-150400.5.69.1 as a component of Container suse/manager/4.3/proxy-salt-broker:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/manager/4.3/proxy-salt-broker:latest">
      <FullProductName ProductID="Container suse/manager/4.3/proxy-salt-broker:latest:libcurl4-8.14.1-150400.5.69.1">libcurl4-8.14.1-150400.5.69.1 as a component of Container suse/manager/4.3/proxy-salt-broker:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sle-micro-rancher/5.3:latest">
      <FullProductName ProductID="Container suse/sle-micro-rancher/5.3:latest:curl-8.14.1-150400.5.69.1">curl-8.14.1-150400.5.69.1 as a component of Container suse/sle-micro-rancher/5.3:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sle-micro-rancher/5.3:latest">
      <FullProductName ProductID="Container suse/sle-micro-rancher/5.3:latest:libcurl4-8.14.1-150400.5.69.1">libcurl4-8.14.1-150400.5.69.1 as a component of Container suse/sle-micro-rancher/5.3:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sle-micro-rancher/5.4:latest">
      <FullProductName ProductID="Container suse/sle-micro-rancher/5.4:latest:curl-8.14.1-150400.5.69.1">curl-8.14.1-150400.5.69.1 as a component of Container suse/sle-micro-rancher/5.4:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sle-micro-rancher/5.4:latest">
      <FullProductName ProductID="Container suse/sle-micro-rancher/5.4:latest:libcurl4-8.14.1-150400.5.69.1">libcurl4-8.14.1-150400.5.69.1 as a component of Container suse/sle-micro-rancher/5.4:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sle-micro/5.5:latest">
      <FullProductName ProductID="Container suse/sle-micro/5.5:latest:libcurl4-8.14.1-150400.5.69.1">libcurl4-8.14.1-150400.5.69.1 as a component of Container suse/sle-micro/5.5:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sle-micro/base-5.5:latest">
      <FullProductName ProductID="Container suse/sle-micro/base-5.5:latest:curl-8.14.1-150400.5.69.1">curl-8.14.1-150400.5.69.1 as a component of Container suse/sle-micro/base-5.5:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sle-micro/base-5.5:latest">
      <FullProductName ProductID="Container suse/sle-micro/base-5.5:latest:libcurl4-8.14.1-150400.5.69.1">libcurl4-8.14.1-150400.5.69.1 as a component of Container suse/sle-micro/base-5.5:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sle-micro/kvm-5.5:latest">
      <FullProductName ProductID="Container suse/sle-micro/kvm-5.5:latest:libcurl4-8.14.1-150400.5.69.1">libcurl4-8.14.1-150400.5.69.1 as a component of Container suse/sle-micro/kvm-5.5:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sle-micro/rt-5.5:latest">
      <FullProductName ProductID="Container suse/sle-micro/rt-5.5:latest:libcurl4-8.14.1-150400.5.69.1">libcurl4-8.14.1-150400.5.69.1 as a component of Container suse/sle-micro/rt-5.5:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:curl-8.14.1-150400.5.69.1">curl-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl-devel-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libcurl-devel-8.14.1-150400.5.69.1">libcurl-devel-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libcurl4-8.14.1-150400.5.69.1">libcurl4-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-32bit-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libcurl4-32bit-8.14.1-150400.5.69.1">libcurl4-32bit-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:curl-8.14.1-150400.5.69.1">curl-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl-devel-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:libcurl-devel-8.14.1-150400.5.69.1">libcurl-devel-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:libcurl4-8.14.1-150400.5.69.1">libcurl4-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-32bit-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:libcurl4-32bit-8.14.1-150400.5.69.1">libcurl4-32bit-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:curl-8.14.1-150400.5.69.1">curl-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl-devel-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libcurl-devel-8.14.1-150400.5.69.1">libcurl-devel-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libcurl4-8.14.1-150400.5.69.1">libcurl4-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-32bit-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libcurl4-32bit-8.14.1-150400.5.69.1">libcurl4-32bit-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:curl-8.14.1-150400.5.69.1">curl-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl-devel-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:libcurl-devel-8.14.1-150400.5.69.1">libcurl-devel-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:libcurl4-8.14.1-150400.5.69.1">libcurl4-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-32bit-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:libcurl4-32bit-8.14.1-150400.5.69.1">libcurl4-32bit-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Installer Updates 15 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Installer Updates 15 SP4:libcurl4-8.14.1-150400.5.69.1">libcurl4-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise Installer Updates 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Installer Updates 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Installer Updates 15 SP5:libcurl4-8.14.1-150400.5.69.1">libcurl4-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise Installer Updates 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Micro 5.3">
      <FullProductName ProductID="SUSE Linux Enterprise Micro 5.3:curl-8.14.1-150400.5.69.1">curl-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise Micro 5.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Micro 5.3">
      <FullProductName ProductID="SUSE Linux Enterprise Micro 5.3:libcurl4-8.14.1-150400.5.69.1">libcurl4-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise Micro 5.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Micro 5.4">
      <FullProductName ProductID="SUSE Linux Enterprise Micro 5.4:curl-8.14.1-150400.5.69.1">curl-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise Micro 5.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Micro 5.4">
      <FullProductName ProductID="SUSE Linux Enterprise Micro 5.4:libcurl4-8.14.1-150400.5.69.1">libcurl4-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise Micro 5.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Micro 5.5">
      <FullProductName ProductID="SUSE Linux Enterprise Micro 5.5:curl-8.14.1-150400.5.69.1">curl-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise Micro 5.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Micro 5.5">
      <FullProductName ProductID="SUSE Linux Enterprise Micro 5.5:libcurl4-8.14.1-150400.5.69.1">libcurl4-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise Micro 5.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP4-LTSS:curl-8.14.1-150400.5.69.1">curl-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise Server 15 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl-devel-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP4-LTSS:libcurl-devel-8.14.1-150400.5.69.1">libcurl-devel-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise Server 15 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP4-LTSS:libcurl4-8.14.1-150400.5.69.1">libcurl4-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise Server 15 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-32bit-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP4-LTSS:libcurl4-32bit-8.14.1-150400.5.69.1">libcurl4-32bit-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise Server 15 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP5-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP5-LTSS:curl-8.14.1-150400.5.69.1">curl-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise Server 15 SP5-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl-devel-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP5-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP5-LTSS:libcurl-devel-8.14.1-150400.5.69.1">libcurl-devel-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise Server 15 SP5-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP5-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP5-LTSS:libcurl4-8.14.1-150400.5.69.1">libcurl4-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise Server 15 SP5-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-32bit-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP5-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP5-LTSS:libcurl4-32bit-8.14.1-150400.5.69.1">libcurl4-32bit-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise Server 15 SP5-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP4:curl-8.14.1-150400.5.69.1">curl-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl-devel-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP4:libcurl-devel-8.14.1-150400.5.69.1">libcurl-devel-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP4:libcurl4-8.14.1-150400.5.69.1">libcurl4-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-32bit-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP4:libcurl4-32bit-8.14.1-150400.5.69.1">libcurl4-32bit-8.14.1-150400.5.69.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy LTS 4.3">
      <FullProductName ProductID="SUSE Manager Proxy LTS 4.3:curl-8.14.1-150400.5.69.1">curl-8.14.1-150400.5.69.1 as a component of SUSE Manager Proxy LTS 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl-devel-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy LTS 4.3">
      <FullProductName ProductID="SUSE Manager Proxy LTS 4.3:libcurl-devel-8.14.1-150400.5.69.1">libcurl-devel-8.14.1-150400.5.69.1 as a component of SUSE Manager Proxy LTS 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy LTS 4.3">
      <FullProductName ProductID="SUSE Manager Proxy LTS 4.3:libcurl4-8.14.1-150400.5.69.1">libcurl4-8.14.1-150400.5.69.1 as a component of SUSE Manager Proxy LTS 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-32bit-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy LTS 4.3">
      <FullProductName ProductID="SUSE Manager Proxy LTS 4.3:libcurl4-32bit-8.14.1-150400.5.69.1">libcurl4-32bit-8.14.1-150400.5.69.1 as a component of SUSE Manager Proxy LTS 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="curl-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server LTS 4.3">
      <FullProductName ProductID="SUSE Manager Server LTS 4.3:curl-8.14.1-150400.5.69.1">curl-8.14.1-150400.5.69.1 as a component of SUSE Manager Server LTS 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl-devel-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server LTS 4.3">
      <FullProductName ProductID="SUSE Manager Server LTS 4.3:libcurl-devel-8.14.1-150400.5.69.1">libcurl-devel-8.14.1-150400.5.69.1 as a component of SUSE Manager Server LTS 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server LTS 4.3">
      <FullProductName ProductID="SUSE Manager Server LTS 4.3:libcurl4-8.14.1-150400.5.69.1">libcurl4-8.14.1-150400.5.69.1 as a component of SUSE Manager Server LTS 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-32bit-8.14.1-150400.5.69.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server LTS 4.3">
      <FullProductName ProductID="SUSE Manager Server LTS 4.3:libcurl4-32bit-8.14.1-150400.5.69.1">libcurl4-32bit-8.14.1-150400.5.69.1 as a component of SUSE Manager Server LTS 4.3</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">curl's websocket code did not update the 32 bit mask pattern for each new
 outgoing frame as the specification says. Instead it used a fixed mask that
persisted and was used throughout the entire connection.

A predictable mask pattern allows for a malicious server to induce traffic
between the two communicating parties that could be interpreted by an involved
proxy (configured or transparent) as genuine, real, HTTP traffic with content
and thereby poison its cache. That cached poisoned content could then be
served to all users of that proxy.</Note>
    </Notes>
    <CVE>CVE-2025-10148</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Container suse/manager/4.3/proxy-httpd:latest:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/manager/4.3/proxy-httpd:latest:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/manager/4.3/proxy-salt-broker:latest:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/manager/4.3/proxy-salt-broker:latest:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/sle-micro-rancher/5.3:latest:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/sle-micro-rancher/5.3:latest:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/sle-micro-rancher/5.4:latest:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/sle-micro-rancher/5.4:latest:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/sle-micro/5.5:latest:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/sle-micro/base-5.5:latest:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/sle-micro/base-5.5:latest:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/sle-micro/kvm-5.5:latest:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/sle-micro/rt-5.5:latest:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libcurl-devel-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libcurl4-32bit-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:libcurl-devel-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:libcurl4-32bit-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libcurl-devel-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libcurl4-32bit-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:libcurl-devel-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:libcurl4-32bit-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Installer Updates 15 SP4:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Installer Updates 15 SP5:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.3:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.3:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.4:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.4:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.5:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.5:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP4-LTSS:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP4-LTSS:libcurl-devel-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP4-LTSS:libcurl4-32bit-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP4-LTSS:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP5-LTSS:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP5-LTSS:libcurl-devel-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP5-LTSS:libcurl4-32bit-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP5-LTSS:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP4:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP4:libcurl-devel-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP4:libcurl4-32bit-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP4:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Manager Proxy LTS 4.3:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Manager Proxy LTS 4.3:libcurl-devel-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Manager Proxy LTS 4.3:libcurl4-32bit-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Manager Proxy LTS 4.3:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Manager Server LTS 4.3:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Manager Server LTS 4.3:libcurl-devel-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Manager Server LTS 4.3:libcurl4-32bit-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Manager Server LTS 4.3:libcurl4-8.14.1-150400.5.69.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2025/suse-su-202503267-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2025-10148.html</URL>
        <Description>CVE-2025-10148</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1249348</URL>
        <Description>SUSE Bug 1249348</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">1. A cookie is set using the `secure` keyword for `https://target`
2. curl is redirected to or otherwise made to speak with `http://target` (same
   hostname, but using clear text HTTP) using the same cookie set
3. The same cookie name is set - but with just a slash as path (`path='/'`).
   Since this site is not secure, the cookie *should* just be ignored.
4. A bug in the path comparison logic makes curl read outside a heap buffer
   boundary

The bug either causes a crash or it potentially makes the comparison come to
the wrong conclusion and lets the clear-text site override the contents of the
secure cookie, contrary to expectations and depending on the memory contents
immediately following the single-byte allocation that holds the path.

The presumed and correct behavior would be to plainly ignore the second set of
the cookie since it was already set as secure on a secure host so overriding
it on an insecure host should not be okay.</Note>
    </Notes>
    <CVE>CVE-2025-9086</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Container suse/manager/4.3/proxy-httpd:latest:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/manager/4.3/proxy-httpd:latest:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/manager/4.3/proxy-salt-broker:latest:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/manager/4.3/proxy-salt-broker:latest:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/sle-micro-rancher/5.3:latest:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/sle-micro-rancher/5.3:latest:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/sle-micro-rancher/5.4:latest:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/sle-micro-rancher/5.4:latest:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/sle-micro/5.5:latest:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/sle-micro/base-5.5:latest:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/sle-micro/base-5.5:latest:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/sle-micro/kvm-5.5:latest:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>Container suse/sle-micro/rt-5.5:latest:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libcurl-devel-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libcurl4-32bit-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:libcurl-devel-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:libcurl4-32bit-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libcurl-devel-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libcurl4-32bit-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:libcurl-devel-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:libcurl4-32bit-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Installer Updates 15 SP4:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Installer Updates 15 SP5:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.3:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.3:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.4:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.4:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.5:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.5:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP4-LTSS:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP4-LTSS:libcurl-devel-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP4-LTSS:libcurl4-32bit-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP4-LTSS:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP5-LTSS:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP5-LTSS:libcurl-devel-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP5-LTSS:libcurl4-32bit-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP5-LTSS:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP4:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP4:libcurl-devel-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP4:libcurl4-32bit-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP4:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Manager Proxy LTS 4.3:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Manager Proxy LTS 4.3:libcurl-devel-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Manager Proxy LTS 4.3:libcurl4-32bit-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Manager Proxy LTS 4.3:libcurl4-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Manager Server LTS 4.3:curl-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Manager Server LTS 4.3:libcurl-devel-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Manager Server LTS 4.3:libcurl4-32bit-8.14.1-150400.5.69.1</ProductID>
        <ProductID>SUSE Manager Server LTS 4.3:libcurl4-8.14.1-150400.5.69.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2025/suse-su-202503267-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2025-9086.html</URL>
        <Description>CVE-2025-9086</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1249191</URL>
        <Description>SUSE Bug 1249191</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
