[CLSA-2026:1786007050] Fix CVE(s): CVE-2026-8932
Type:
security
Severity:
Important
Release date:
2026-08-06 09:04:22 UTC
Description:
* SECURITY UPDATE: connection reuse ignored client-certificate config - debian/patches/CVE-2026-8932.patch: promote the client certificate type, private key, key type and key password into ssl_primary_config so the connection-reuse and session-cache match checks cover the full mTLS client credential, in lib/urldata.h, lib/url.c, lib/vtls/vtls.c and the TLS/ldap/ssh consumers, so a reused connection cannot inherit a different client credential. - CVE-2026-8932
CVEs fixed:
Updated packages:
  • curl_7.58.0-2ubuntu3.24+tuxcare.els13_amd64.deb
    sha:02b98360f5ab2bcd642d57447503cf2aa5a3b8fb
  • libcurl3-gnutls_7.58.0-2ubuntu3.24+tuxcare.els13_amd64.deb
    sha:7daddab3c80a2357e4910f2f853ea630f048049a
  • libcurl3-nss_7.58.0-2ubuntu3.24+tuxcare.els13_amd64.deb
    sha:3af443309b74c3e2b2c498e9e5e2f5642c542d25
  • libcurl4_7.58.0-2ubuntu3.24+tuxcare.els13_amd64.deb
    sha:4bb1898628a5d8c1cefff9271ee3c28be6532c39
  • libcurl4-doc_7.58.0-2ubuntu3.24+tuxcare.els13_all.deb
    sha:05b69b2f91d7d3c04fe9b0e739c27a60b9ae97b6
  • libcurl4-gnutls-dev_7.58.0-2ubuntu3.24+tuxcare.els13_amd64.deb
    sha:bb865675ddeeda076574073a2a0877fe42bfe393
  • libcurl4-nss-dev_7.58.0-2ubuntu3.24+tuxcare.els13_amd64.deb
    sha:7e3484fac2e0cdb2008be3af846d4774481c76a6
  • libcurl4-openssl-dev_7.58.0-2ubuntu3.24+tuxcare.els13_amd64.deb
    sha:8db017e2702089493ed6eb8966df23d86ffa7a94
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.