Impact
Libcurl’s SMB connection pooling logic contains a coding error that can cause the client to reuse an SMB connection to the wrong share. The flaw may result in a download of an unintended file or an upload to the wrong location while still authenticating with the same credentials and connecting to the same server. This breach of data integrity could allow an attacker or a misconfigured application to expose or overwrite incorrect data, as identified by the CWE identifiers representing improper reuse of resources, improper input validation, and insecure design.
Affected Systems
The cURL client, which incorporates libcurl, is specifically mentioned as an affected vendor/product. Because libcurl is a widely used library, any application that relies on cURL to perform SMB transfers could also be affected, provided it uses SMB functionality. The precise version range is not listed, so any libcurl installation that has not received the fix may be vulnerable.
Risk and Exploitability
The CVSS score of 7.5 classifies the issue as high severity, while the EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation. The vulnerability is not included in the CISA KEV catalog. An attacker would need to influence the SMB transfer parameters set by the vendor application, for example by supplying crafted requests or modifying local configuration, to trigger a cross‑share data transfer.
OpenCVE Enrichment
Ubuntu USN