Pull to refresh
Logo
ARM64 compiler bugs in GCC and Rust open vulnerabilities in curl

ARM64 compiler bugs in GCC and Rust open vulnerabilities in curl

New Capabilities

Two optimization miscompiles found by curl security researcher Viktor Szakáts, days before a 22-CVE release

Yesterday: curl 8.23.0 announced

Overview

Updated 54 minutes ago

curl security researcher Viktor Szakáts found two ARM64-only compiler miscompiles that silently produced vulnerable machine code in curl: one in GCC 15/16, one in Rust. The bugs turn optimization errors into exploitable flaws that appear only on ARM64 hardware, from Apple Silicon Macs to AWS Graviton servers.

The disclosure lands eight days before curl 8.23.0 ships on October 14 with fixes for 22 CVEs, including one rated HIGH. Stenberg pulled the release forward after one particular vulnerability report that highlighted a significant flaw. The release notes will show whether the miscompiles are part of that report.

Why it matters

A miscompile means the bug is invisible in source — it exists only in the machine code shipped to billions of ARM64 devices.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

2
Compiler miscompiles found
One in GCC 15/16, one in Rust, both ARM64-specific.
22
CVEs fixed in curl 8.23.0
Includes one rated HIGH (CVE-2026-92392); details public October 14.
30+ billion
Devices running curl
Scale of curl's install base across operating systems, appliances, and infrastructure.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

People Involved

Organizations Involved

Timeline

June 2026 October 2026

4 events Latest: Yesterday
Tap a bar to jump to that date
  1. curl 8.23.0 release scheduled

    Upcoming Release

    All 22 vulnerability details, including CVE-2026-92392, become public that morning.

  2. curl 8.23.0 announced

    Latest Statement

    Stenberg says release ships October 14 with 22 fixes, one rated HIGH.

  3. Two ARM64 miscompiles disclosed

    Disclosure

    Szakáts reports GCC 15/16 and Rust miscompiles; Stenberg confirms on Mastodon.

  4. curl 8.21.0 fixes 18 CVEs

    Release

    Includes CVE-2026-8932, the oldest curl vulnerability ever reported, dating to 2001.

Scenarios

1

curl 8.23.0 fixes the miscompile vulnerabilities

Likely Resolves by Nov 15, 2026

Discussed by: Curl lead Daniel Stenberg, who announced the October 14 release on his blog

Curl ships 8.23.0 on October 14 with fixes for 22 CVEs. Stenberg pulled the release date forward after receiving one significant vulnerability report. When the release notes appear that morning, they will show whether the ARM64 miscompiles are among the fixed issues. If they are, patching becomes a straightforward upgrade for most users.

2

GCC and Rust ship compiler fixes

Likely Resolves by Q2 2027

Discussed by: Compiler maintainers, who typically release point updates for confirmed miscompilations

GCC and Rust project maintainers treat confirmed miscompiles as high-priority bugs. GCC would fix the ARM64 optimization path in a 15.x or 16.x point release, or in the next major version. Rust ships a new release every six weeks. The fixes would be verifiable through release notes that name the curl-reported bug.

3

The same miscompiles surface in other software

Uncertain Resolves by End of 2027

Discussed by: Security researchers who study compiler bug classes, including Szakáts

If the ARM64 optimization bugs are triggered by general code patterns rather than curl-specific constructs, other security-sensitive software built with GCC 15/16 or Rust could carry identical flaws. Audits of comparable code paths would determine whether the exposure extends beyond curl.

Historical Context

2 moments from history that rhyme with this story — and how they unfolded.

May 2008

Debian OpenSSL weak keys (CVE-2008-0166)

A Debian packager removed a line from OpenSSL's random-number seeding code in 2006. The change made the PRNG output predictable, so every SSH and SSL key generated on affected Debian systems had only a small number of possible values. Researchers found the flaw in 2008.

Then

Millions of keys across Debian and Ubuntu systems had to be regenerated within days.

Now

It became a textbook case of how a small change outside upstream source can create a security catastrophe.

Why this matters now

Like the curl miscompiles, the vulnerability lived not in the application's logic but in the layer that turns source into a usable system — here the build and packaging process, there the compiler.

February-March 2024

xz-utils supply-chain backdoor (2024)

A contributor later identified as acting with malicious intent added obfuscated code to xz-utils, a compression library widely used in Linux distributions. The code targeted OpenSSH's build process to plant a backdoor in sshd on affected systems. It was discovered before wide deployment.

Then

The backdoor was neutralized within days of discovery.

Now

It drove a reckoning about trusting the build toolchain and the maintainers who control it.

Why this matters now

The curl case is the same layer failing without malice: the compiler generated faulty code. Both show that the components that build software are themselves security-critical.

Sources

(7)