Release date:
2026-08-13 02:39:13 UTC
Description:
* SECURITY UPDATE: stale custom cookie host causes cookie leak
- debian/patches/CVE-2026-6276.patch: clear the remembered custom
Host: name at the start of every request in lib/http.c.
- CVE-2026-6276
* SECURITY UPDATE: wrong STARTTLS connection reuse
- debian/patches/CVE-2026-8286.patch: require a matching SSL
configuration when reusing a connection for a transfer that may
upgrade to TLS in lib/url.c.
- CVE-2026-8286
* SECURITY UPDATE: env-set cross-proxy Digest auth state leak
- debian/patches/CVE-2026-8927.patch: flush the proxy Digest state
when the proxy read from the environment changes in lib/url.c,
lib/urldata.h.
- CVE-2026-8927
* SECURITY UPDATE: incomplete mTLS config in connection reuse and TLS
session cache
- debian/patches/CVE-2026-8932.patch: include the client private key
options in the primary SSL config so connection reuse and the TLS
session cache compare them in lib/url.c, lib/urldata.h,
lib/vtls/vtls.c.
- CVE-2026-8932
* SECURITY UPDATE: HTTP/2 push headers memory leak
- debian/patches/CVE-2024-2398.patch: free the whole set of push
headers on the array-growth failure path in lib/http2.c.
- CVE-2024-2398
Updated packages:
-
curl_7.64.0-4+deb10u9+tuxcare.els5_amd64.deb
sha:4cf573e65b96ff075057021602dde1579b7f8f2b
-
libcurl3-gnutls_7.64.0-4+deb10u9+tuxcare.els5_amd64.deb
sha:8d37a066d5fa3ba729fdd16a928d76ad8f49ff54
-
libcurl3-nss_7.64.0-4+deb10u9+tuxcare.els5_amd64.deb
sha:6e2c5cb910e3ef1284b435dbdb09f7ecd4f9658e
-
libcurl4_7.64.0-4+deb10u9+tuxcare.els5_amd64.deb
sha:6296d6e0c09caae5bc19ad03dd1e38543f0c3193
-
libcurl4-doc_7.64.0-4+deb10u9+tuxcare.els5_all.deb
sha:3220ab7988a68ce62cfb9e939e2e6c6355d4b6b2
-
libcurl4-gnutls-dev_7.64.0-4+deb10u9+tuxcare.els5_amd64.deb
sha:ee410e6915c253059d9a920f18c96b26bc5efc0b
-
libcurl4-nss-dev_7.64.0-4+deb10u9+tuxcare.els5_amd64.deb
sha:f4c2ccc07d1f1319c04998703cc07852e1ffd9b3
-
libcurl4-openssl-dev_7.64.0-4+deb10u9+tuxcare.els5_amd64.deb
sha:bf677f47222a3712beb9e48a440a73632dd70407
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.