CVE-2025-0665
HIGHDescription
libcurl would wrongly close the same eventfd file descriptor twice when taking down a connection channel after having completed a threaded name resolve.
Is your site exposed to CVE-2025-0665?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| haxx | curl |
| netapp | bootstrap_os |
| netapp | hci_compute_node |
| netapp | h300s_firmware |
| netapp | h300s |
| netapp | h410c_firmware |
| netapp | h410c |
| netapp | h410s_firmware |
| netapp | h410s |
| netapp | h500s_firmware |
| netapp | h500s |
| netapp | h700s_firmware |
| netapp | h700s |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-0665? +
How severe is CVE-2025-0665? +
What products are affected by CVE-2025-0665? +
How do I check if I'm vulnerable to CVE-2025-0665? +
Related Vulnerabilities
The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the …
libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the …
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes …
Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the …
libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the …
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public …