Curl 8.12.0 (already in-tree) contains fixes for the following CVEs: CVE-2025-0725: gzip integer overflow CVE-2025-0665: eventfd double close CVE-2025-0167: netrc and default credential leak
https://github.com/curl/curl/discussions/16259
8.12.1 is out: https://github.com/curl/curl/releases/tag/curl-8_12_1
8.12.1 looks better, the regression from 8.12.0 is gone (at least our use case).
commit 893edb6df0a8cbe0902fb4b6d3e8f09a782fd349 (origin/master, origin/HEAD) Author: Matt Jolly <kangie@gentoo.org> Date: Fri Feb 14 22:12:34 2025 +1000 net-misc/curl: add 8.12.1 Signed-off-by: Matt Jolly <kangie@gentoo.org>
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=d682a759788a14c1d3eea5bf48e0bff7d01f98d7 commit d682a759788a14c1d3eea5bf48e0bff7d01f98d7 Author: Christopher Fore <csfore@posteo.net> AuthorDate: 2025-03-30 23:15:21 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2025-04-03 15:25:59 +0000 net-misc/curl: drop 8.11.1-r2 Bug: https://bugs.gentoo.org/949330 Signed-off-by: Christopher Fore <csfore@posteo.net> Closes: https://github.com/gentoo/gentoo/pull/41393 Signed-off-by: Sam James <sam@gentoo.org> net-misc/curl/Manifest | 2 - net-misc/curl/curl-8.11.1-r2.ebuild | 384 ------------------------------------ 2 files changed, 386 deletions(-)