CVE-2018-16890: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 5.4% chance of exploitation in the next 30 days.

libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a malicious or broken NTLM server could trick libcurl to accept a bad length + offset combination that would lead to a buffer read out-of-bounds.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
  • Debian Debian Linux: version 9.0 only
  • F5 BIG-IP Access Policy Manager: from 13.1.0, up to and including 13.1.3; from 14.0.0, up to and including 14.1.2; from 15.0.0, up to and including 15.0.1
  • Haxx Libcurl: from 7.36.0, before 7.64.0 (fixed in 7.64.0)
  • Netapp Clustered Data Ontap: any version
  • Oracle Communications Operations Monitor: version 3.4 only; version 4.0 only
  • Oracle HTTP Server: version 12.2.1.3.0 only
  • Oracle Secure Global Desktop: version 5.4 only
  • Red Hat Enterprise Linux: version 8.0 only
  • Siemens Sinema Remote Connect Client: up to and including 2.0

Published 2019-02-06. Last modified 2026-06-17.