[CLSA-2026:1786475233] curl: Fix of CVE-2026-12064
Type:
security
Severity:
Important
Release date:
2026-08-11 19:07:24 UTC
Description:
- CVE-2026-12064: honour --proto-default in the command line tool instead of guessing the scheme from the hostname, so the SSH host verification options are applied to a schemeless URL transferred over SCP or SFTP
CVEs fixed:
Updated packages:
  • curl-8.3.0-1.amzn2.0.12.tuxcare.els6.x86_64.rpm
    sha:c128155b4f7d67d004e945522db9ae5a50d45c5696c0ab52109eec37b3fe2b16
  • libcurl-8.3.0-1.amzn2.0.12.tuxcare.els6.i686.rpm
    sha:5f0a1901accee278635b5524d5a4a6157ddf9a30433c569ceccaecdd48474186
  • libcurl-8.3.0-1.amzn2.0.12.tuxcare.els6.x86_64.rpm
    sha:56446288eaadfd32d9b23b946cdf44be3394114da3ee347990cb1e01c8d031b1
  • libcurl-devel-8.3.0-1.amzn2.0.12.tuxcare.els6.x86_64.rpm
    sha:df81d4c03016652b4c27c89c47e76ba70f9aff8a5222bd979be4890cdd42c3b6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.