[CLSA-2026:1785925031] curl: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-05 10:17:23 UTC
Description:
- CVE-2026-8927: flush the proxy Digest authentication state when the proxy read from an environment variable differs from the one that state was established for, so a Proxy-Authorization header computed for one proxy is not sent to a different proxy on a reused handle - CVE-2026-8932: compare the client certificate type and the private key, its type, password and blob when matching a connection for reuse and when matching a cached TLS session, so a transfer cannot silently inherit another handle's authenticated client identity
Updated packages:
  • curl-7.76.1-31.el9_6.1.tuxcare.els17.x86_64.rpm
    sha:6d161fb392fc7c3db8625657650bb9c93f9cebe4fc0e706e60fc1af0bdf8bee8
  • curl-minimal-7.76.1-31.el9_6.1.tuxcare.els17.x86_64.rpm
    sha:bb34bc58aca9b1c9dc0b4882f48cfc57fba093296028cd11bd3f7075daa543f0
  • libcurl-7.76.1-31.el9_6.1.tuxcare.els17.i686.rpm
    sha:258b17e47101cebc978886330170e76c651ab2636e42d8fa4b9675a580a51378
  • libcurl-7.76.1-31.el9_6.1.tuxcare.els17.x86_64.rpm
    sha:13991e559ccd124bcb5e18a8ef1775d76b9f5449b96ef8a2390a2dcf8b340aa6
  • libcurl-devel-7.76.1-31.el9_6.1.tuxcare.els17.i686.rpm
    sha:27b79ae5e6683645687ca0c6f17917e3b5a4ffa2e2d60e3a270099901f36cb62
  • libcurl-devel-7.76.1-31.el9_6.1.tuxcare.els17.x86_64.rpm
    sha:13d9edb7c36b7fc61d18c47057192e45617e3cc054a07f2d2367fc343c2418a2
  • libcurl-minimal-7.76.1-31.el9_6.1.tuxcare.els17.i686.rpm
    sha:41f2665db5cfca72f1956f0c74b465b84774d42092cc1865d6c3770fbed037d5
  • libcurl-minimal-7.76.1-31.el9_6.1.tuxcare.els17.x86_64.rpm
    sha:d08137fc4d650de9fa064083305030c50f97363f5a4bebb29d4e55647d7770ff
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.