[CLSA-2026:1786091577] curl: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-08-07 08:33:07 UTC
Description:
- CVE-2026-8458: tie the requested SASL/SPNEGO service name to the connection and compare it when matching an existing connection for reuse, so a Negotiate authenticated connection is not reused for a transfer that asked for a different service - CVE-2026-8926: discard a .netrc entry that matches the host but whose login does not match the user given in the URL, so the password that belongs to another user of that host is no longer returned as a successful lookup
Updated packages:
  • curl-7.76.1-31.el9_6.1.tuxcare.els18.x86_64.rpm
    sha:5aa62ef2435396fc1ccac62ebcc294ed073034777e80f599b3e476b37a6c9506
  • curl-minimal-7.76.1-31.el9_6.1.tuxcare.els18.x86_64.rpm
    sha:870d1e0f822d1e4fb27065983da0306c287d34f927872f1019d27fe8c7b95dec
  • libcurl-7.76.1-31.el9_6.1.tuxcare.els18.i686.rpm
    sha:c999036badae648db23f276e7a773390b4e7a703616943d70b2959b4b1479e86
  • libcurl-7.76.1-31.el9_6.1.tuxcare.els18.x86_64.rpm
    sha:b7c4e6440510fbef6e579b9ca4c6d1033d245fe387fb62bbe0c9615fbba6f38a
  • libcurl-devel-7.76.1-31.el9_6.1.tuxcare.els18.i686.rpm
    sha:1cda162518f81a20a6f88134f524796802de372edafd9e8bd476e4f055d44b06
  • libcurl-devel-7.76.1-31.el9_6.1.tuxcare.els18.x86_64.rpm
    sha:f51c98175c0dc4cd86b7e79e824fb8b483bd5121cbcf813c806e3f82feb64185
  • libcurl-minimal-7.76.1-31.el9_6.1.tuxcare.els18.i686.rpm
    sha:0425f4f9dc2e3a109337067d2c67744a2927250cceb20b3c5560f42f87a00fc8
  • libcurl-minimal-7.76.1-31.el9_6.1.tuxcare.els18.x86_64.rpm
    sha:1bdf88f44f2dc69d77a4cc5ef960e2873dabf12672277dde28c28bef416fe952
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.