Ubuntu USN-8487-2 Corrects the curl CVE-2026-8927 Fix

P2 — VALIDATE AND UPDATENot provided by the authority · Not provided by the authorityEXPLOITATION: NOT STATED

Quick Answer

Canonical published USN-8487-2 because USN-8487-1 contained an incomplete fix for CVE-2026-8927. The follow-up applies to Ubuntu 14.04 LTS systems using Legacy Support. Install curl 7.35.0-1ubuntu2.20+esm23, validate affected transfer and proxy-authentication workflows, and retain package evidence. Canonical does not state a CVSS base score in this notice.

Confirm Scope And Apply The Supported Fix

What to do now: Identify Ubuntu 14.04 LTS systems using Legacy Support, verify the installed curl source-package version, apply 7.35.0-1ubuntu2.20+esm23, validate transfer and proxy-authentication workflows, and retain package evidence.

Open the authoritative advisory

Last verified: 2026-09-29 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.

Scope And Authority

Product scopeUbuntu 14.04 LTS (Trusty) curl packages covered by Legacy Support
AdvisoryUSN-8487-2
CVECVE-2026-8927
Authoritative release date2026-09-28 20:29:10.831741 UTC
Authority revision dateNo separate material revision date stated by Canonical when verified
Affected versionsUbuntu 14.04 LTS (Trusty) systems using the Legacy Support repository and a curl source package before 7.35.0-1ubuntu2.20+esm23 for the CVE-2026-8927 correction.
Fixed versioncurl 7.35.0-1ubuntu2.20+esm23 for Ubuntu 14.04 LTS Legacy Support
CVSS base scoreNot provided by the authority
CVSS severityNot provided by the authority
Exploitation statusNot stated by the authority; no exploitation claim is inferred.

What Changed

Canonical states that USN-8487-1 contained an incomplete fix for CVE-2026-8927. USN-8487-2 replaces the affected Ubuntu 14.04 LTS Legacy Support curl package with the corrected build.

What To Validate Now

  1. Inventory. Locate Ubuntu 14.04 LTS systems enrolled in Legacy Support, record the curl source-package version, repository pocket, owner, and services or applications linked to libcurl.
  2. Establish applicability. Match systems to USN-8487-2's Ubuntu 14.04 LTS Legacy Support scope. Do not extend this follow-up notice to other Ubuntu releases merely because USN-8487-1 discussed them.
  3. Remediate. Install curl 7.35.0-1ubuntu2.20+esm23 from the supported Ubuntu Legacy Support repository using normal change control.
  4. Validate. Confirm the installed source-package version, restart or reload long-running consumers where required, exercise representative curl and proxy-authentication workflows, monitor for regressions, and retain results.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

This is a regression follow-up for an incomplete prior fix, not evidence that every system named in the original advisory remains affected. Preserve repository entitlement and test applications that embed libcurl.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.