CVE-2026-5773
Publication date 29 April 2026
Last updated 29 April 2026
Ubuntu priority
Description
libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers.
Read the notes from the security team
Why is this CVE low priority?
curl is dropping support for SMB later in 2026 and only supports SMB version 1
Mitigation
Avoid using SMB
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| curl | 26.04 LTS resolute |
Needs evaluation
|
| 25.10 questing |
Vulnerable
|
|
| 24.04 LTS noble |
Vulnerable
|
|
| 22.04 LTS jammy |
Vulnerable
|
|
| 20.04 LTS focal |
Vulnerable
|
|
| 18.04 LTS bionic |
Vulnerable
|
|
| 16.04 LTS xenial |
Vulnerable
|
|
| 14.04 LTS trusty |
Not affected
|