libcurl would wrongly close the same eventfd file descriptor twice when taking down a connection channel after having completed a threaded name resolve.
The product attempts to close or release a resource or handle more than once, without any successful open between the close operations.
Link | Tags |
---|---|
https://curl.se/docs/CVE-2025-0665.json | vendor advisory |
https://curl.se/docs/CVE-2025-0665.html | vendor advisory |
https://hackerone.com/reports/2954286 | third party advisory issue tracking exploit |
http://www.openwall.com/lists/oss-security/2025/02/05/2 | mailing list third party advisory |
http://www.openwall.com/lists/oss-security/2025/02/05/5 | mailing list third party advisory |
https://security.netapp.com/advisory/ntap-20250306-0007/ | third party advisory |