[CLSA-2026:1785925784] curl: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-05 10:29:58 UTC
Description:
- CVE-2026-8927: flush the proxy Digest authentication state when the proxy read from an environment variable differs from the one that state was established for, so a Proxy-Authorization header computed for one proxy is not sent to a different proxy on a reused handle - CVE-2026-8932: compare the client certificate type and the private key, its type, password and blob when matching a connection for reuse and when matching a cached TLS session, so a transfer cannot silently inherit another handle's authenticated client identity
Updated packages:
  • curl-7.76.1-31.el9_2.1.tuxcare.els17.x86_64.rpm
    sha:90d85d434ce8963c328a7111bdae05440f25d6f6f3fd8b89acf2e5928290daa1
  • curl-minimal-7.76.1-31.el9_2.1.tuxcare.els17.x86_64.rpm
    sha:b873b8bafb1e611f54e1301c1eb78215cabaae7d21918db20e4592eaecdc78ae
  • libcurl-7.76.1-31.el9_2.1.tuxcare.els17.i686.rpm
    sha:ba6fcce775fce196f5ccff918df11e4934d2fe54a0ecbb7fa5127469db3419e2
  • libcurl-7.76.1-31.el9_2.1.tuxcare.els17.x86_64.rpm
    sha:a6e6208558b5cc89e19c9f21e7fe3c5ed7c8303ce0cd9a14227721fba86a7fa1
  • libcurl-devel-7.76.1-31.el9_2.1.tuxcare.els17.i686.rpm
    sha:2082b8430344368a5f1170700e44a86a9585c6d4cba37116fdffac02de608991
  • libcurl-devel-7.76.1-31.el9_2.1.tuxcare.els17.x86_64.rpm
    sha:7b1d657c5fb648691d87f13db285aa8890c3a314eddb464735a7bbed455d7110
  • libcurl-minimal-7.76.1-31.el9_2.1.tuxcare.els17.i686.rpm
    sha:7757f280c846ec80feafe99ffd15fdbc40ecfacb012f1e5972826402ebd99973
  • libcurl-minimal-7.76.1-31.el9_2.1.tuxcare.els17.x86_64.rpm
    sha:c0b432934f0ba031a416f6ca52f59b1875063ef84f4ae5beeb26e956f174d4df
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.