CVE-2025-0665 Information

Description

libcurl would wrongly close the same eventfd file descriptor twice when taking down a connection channel after having completed a threaded name resolve.

Reference

cve@curl.se http://www.openwall.com/lists/oss-security/2025/02/05/2 http://www.openwall.com/lists/oss-security/2025/02/05/5 https://curl.se/docs/CVE-2025-0665.html https://curl.se/docs/CVE-2025-0665.json https://hackerone.com/reports/2954286 libcurl would wrongly close the same eventfd file descriptor twice when taking down a connection channel after having completed a threaded name resolve.

Share on: