[CLSA-2026:1786092535] curl: Fix of CVE-2026-8932
Type:
security
Severity:
Important
Release date:
2026-08-07 08:49:09 UTC
Description:
- CVE-2026-8932: authentication bypass through connection reuse, where the client certificate type, private key, key type and key password were not part of the SSL configuration compared by Curl_ssl_config_matches(), so an easy handle could inherit another handle's authenticated mTLS connection
CVEs fixed:
Updated packages:
  • curl-7.61.1-22.el8.tuxcare.els22.x86_64.rpm
    sha:77b0c8677f40768448166cd2ea31674fd6b9ff4d72d9d9c9379c724929b61d6a
  • curl-minimal-7.61.1-22.el8.tuxcare.els22.x86_64.rpm
    sha:240abd887502d4da3e53b24174576135d098f651690e4b939fedf969bfec7bfe
  • libcurl-7.61.1-22.el8.tuxcare.els22.i686.rpm
    sha:2b07dc73157be5f658099d2e28d8fbf711d0d787f25764b65111ce495bb9ed72
  • libcurl-7.61.1-22.el8.tuxcare.els22.x86_64.rpm
    sha:1b36bd3b6dfe464e95898f068f66d2cea3d7be86ccae00de2ee37d982dd926dc
  • libcurl-devel-7.61.1-22.el8.tuxcare.els22.i686.rpm
    sha:210c9879af4bbff460b64b6f2a817d7e53f8534bf1e746ae0dac634752544d8c
  • libcurl-devel-7.61.1-22.el8.tuxcare.els22.x86_64.rpm
    sha:95be4e43ac2ecfbcdd8ad3d5c4b9f84d1929c4c91b700239e1d55a7c76d6e968
  • libcurl-minimal-7.61.1-22.el8.tuxcare.els22.i686.rpm
    sha:2771f06938dd58f0e86dbd012843b9cad03382a7572ea18eccc6f97a11d4b041
  • libcurl-minimal-7.61.1-22.el8.tuxcare.els22.x86_64.rpm
    sha:484bffa9100bd15e11ac429ff9cff287ea80795783e51c46f69812ef56f1b207
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.