Release date:
2026-08-06 16:33:58 UTC
Description:
- CVE-2026-8932: authentication bypass through connection reuse, where the
client certificate type, private key, key type and key password were not
part of the SSL configuration compared by Curl_ssl_config_matches(), so an
easy handle could inherit another handle's authenticated mTLS connection
Updated packages:
-
curl-7.61.1-22.el8.tuxcare.els22.x86_64.rpm
sha:5a85904adacff2ab69ff310b84602f090ba015f68ec053478ea78e37e8927b1a
-
curl-minimal-7.61.1-22.el8.tuxcare.els22.x86_64.rpm
sha:736bb89e28b1f04f9a9ca9f4212b5239faae5cd99eca62ea4ba7f31541418810
-
libcurl-7.61.1-22.el8.tuxcare.els22.i686.rpm
sha:796ef399157af66e0fb100623fee30273c6cb785e95bb4529b1fdc8f7b6a9da6
-
libcurl-7.61.1-22.el8.tuxcare.els22.x86_64.rpm
sha:b41617df206e1c4fbd909433c9e163004e5687a5040c4164db1cfe8f70a7a215
-
libcurl-devel-7.61.1-22.el8.tuxcare.els22.i686.rpm
sha:4d330cbdf3715129bd0162dba8c1bd6443869902da1478698394cf489866388c
-
libcurl-devel-7.61.1-22.el8.tuxcare.els22.x86_64.rpm
sha:8a59492b78f8c7d6007e9159222ab959f608f4c39ec648f94feac3f11ca4a16e
-
libcurl-minimal-7.61.1-22.el8.tuxcare.els22.i686.rpm
sha:dfd37eff0a8eec0f3276e7fcfce28f34c71130a4e6f0e2cce364faa7c3056860
-
libcurl-minimal-7.61.1-22.el8.tuxcare.els22.x86_64.rpm
sha:e0dc503b800911f0ca2e1c0595854c909a2092f2dd2c122e788c24e7d505d4e5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.