[CLSA-2026:1786094315] curl: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-08-07 09:18:46 UTC
Description:
- CVE-2026-8458: tie the requested SASL/SPNEGO service name to the connection and compare it when matching an existing connection for reuse, so a Negotiate authenticated connection is not reused for a transfer that asked for a different service - CVE-2026-8926: discard a .netrc entry that matches the host but whose login does not match the user given in the URL, so the password that belongs to another user of that host is no longer returned as a successful lookup
Updated packages:
  • curl-7.76.1-31.el9_2.1.tuxcare.els18.x86_64.rpm
    sha:923f27f2c20e29e60dfec68b47aab66f4a324391c983e88eb6a62aee3619d852
  • curl-minimal-7.76.1-31.el9_2.1.tuxcare.els18.x86_64.rpm
    sha:1dc48df33b6afe02e5601f22a66e55876a61202094fdee6f462b3c97edca203a
  • libcurl-7.76.1-31.el9_2.1.tuxcare.els18.i686.rpm
    sha:f2eb595a116180a279bf5652c9ca8805782b8f6590e60164d8e2f0fcfbaadca7
  • libcurl-7.76.1-31.el9_2.1.tuxcare.els18.x86_64.rpm
    sha:d1cd35b635a6c535af04b46b1454a00ada09550d045de28cdc09ee6c94b45eee
  • libcurl-devel-7.76.1-31.el9_2.1.tuxcare.els18.i686.rpm
    sha:204345a30af27af405c45f73e08bf825c04007ac1b3e15d98d0acd66fda7d8f7
  • libcurl-devel-7.76.1-31.el9_2.1.tuxcare.els18.x86_64.rpm
    sha:a19355d4bd0a61789542640249009fbecc9191ebfee1f4ec495457e11d8b19da
  • libcurl-minimal-7.76.1-31.el9_2.1.tuxcare.els18.i686.rpm
    sha:2eefe77b8d7a98b103dc3be0f5d293a1a3f2972d8018291b7a7a7a0eb95f8aac
  • libcurl-minimal-7.76.1-31.el9_2.1.tuxcare.els18.x86_64.rpm
    sha:cd8a4ea9f4727f89a8e4b09e3e2934712990acebe05c1d86f077fb46c291efad
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.