Release date:
2026-08-07 09:18:46 UTC
Description:
- CVE-2026-8458: tie the requested SASL/SPNEGO service name to the connection
and compare it when matching an existing connection for reuse, so a
Negotiate authenticated connection is not reused for a transfer that asked
for a different service
- CVE-2026-8926: discard a .netrc entry that matches the host but whose login
does not match the user given in the URL, so the password that belongs to
another user of that host is no longer returned as a successful lookup
Updated packages:
-
curl-7.76.1-31.el9_2.1.tuxcare.els18.x86_64.rpm
sha:923f27f2c20e29e60dfec68b47aab66f4a324391c983e88eb6a62aee3619d852
-
curl-minimal-7.76.1-31.el9_2.1.tuxcare.els18.x86_64.rpm
sha:1dc48df33b6afe02e5601f22a66e55876a61202094fdee6f462b3c97edca203a
-
libcurl-7.76.1-31.el9_2.1.tuxcare.els18.i686.rpm
sha:f2eb595a116180a279bf5652c9ca8805782b8f6590e60164d8e2f0fcfbaadca7
-
libcurl-7.76.1-31.el9_2.1.tuxcare.els18.x86_64.rpm
sha:d1cd35b635a6c535af04b46b1454a00ada09550d045de28cdc09ee6c94b45eee
-
libcurl-devel-7.76.1-31.el9_2.1.tuxcare.els18.i686.rpm
sha:204345a30af27af405c45f73e08bf825c04007ac1b3e15d98d0acd66fda7d8f7
-
libcurl-devel-7.76.1-31.el9_2.1.tuxcare.els18.x86_64.rpm
sha:a19355d4bd0a61789542640249009fbecc9191ebfee1f4ec495457e11d8b19da
-
libcurl-minimal-7.76.1-31.el9_2.1.tuxcare.els18.i686.rpm
sha:2eefe77b8d7a98b103dc3be0f5d293a1a3f2972d8018291b7a7a7a0eb95f8aac
-
libcurl-minimal-7.76.1-31.el9_2.1.tuxcare.els18.x86_64.rpm
sha:cd8a4ea9f4727f89a8e4b09e3e2934712990acebe05c1d86f077fb46c291efad
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.