Release date:
2026-08-11 20:34:10 UTC
Description:
* SECURITY UPDATE: connection reuse ignored client-certificate config
- debian/patches/CVE-2026-8932.patch: include the client certificate type,
private key, key type and key password in the connection-reuse and
session-cache match checks in lib/urldata.h, lib/url.c and
lib/vtls/vtls.c, so a reused connection cannot inherit a different
mTLS client credential; also add the missing strequal.h include to
lib/vtls/vtls.c so Curl_safecmp() and Curl_timestrcmp() are declared
rather than reached through an implicit declaration.
- CVE-2026-8932
Updated packages:
-
curl_7.47.0-1ubuntu2.23+tuxcare.els17_amd64.deb
sha:ae6b878bac9cc8b34ae8a4d5c02cd46d9116b519
-
libcurl3_7.47.0-1ubuntu2.23+tuxcare.els17_amd64.deb
sha:957e1389c77dee445b728dbdfec700ed42534f3f
-
libcurl3-gnutls_7.47.0-1ubuntu2.23+tuxcare.els17_amd64.deb
sha:abce170afdacc1344623bd15ddedad38966e5dfb
-
libcurl3-nss_7.47.0-1ubuntu2.23+tuxcare.els17_amd64.deb
sha:357274fc11dea01603a0a216b79d1a6a8625609c
-
libcurl4-doc_7.47.0-1ubuntu2.23+tuxcare.els17_all.deb
sha:dcfffd9c023c61f59905bfcc07e042d2232cb422
-
libcurl4-gnutls-dev_7.47.0-1ubuntu2.23+tuxcare.els17_amd64.deb
sha:223d9c46e59703f1e93d9fabc08acab16f6e8438
-
libcurl4-nss-dev_7.47.0-1ubuntu2.23+tuxcare.els17_amd64.deb
sha:cbf9ea545b88f38599caa8f6bff2e81fe4d4bb68
-
libcurl4-openssl-dev_7.47.0-1ubuntu2.23+tuxcare.els17_amd64.deb
sha:659f332095319b416ad87af4161aecdc8c3558b1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.