[CLSA-2026:1786034295] curl: Fix of CVE-2026-8932
Type:
security
Severity:
Important
Release date:
2026-08-06 16:38:26 UTC
Description:
- CVE-2026-8932: authentication bypass through connection reuse, where the client certificate type, private key, key type and key password were not part of the SSL configuration compared by Curl_ssl_config_matches(), so an easy handle could inherit another handle's authenticated mTLS connection
CVEs fixed:
Updated packages:
  • curl-7.61.1-34.el8.tuxcare.els11.x86_64.rpm
    sha:c402e22871a71ab169069bf2f3e66166a038e288443b577b83c459154b73e9c4
  • curl-minimal-7.61.1-34.el8.tuxcare.els11.x86_64.rpm
    sha:bd1ee80fd311a1dfb43a949d466088a24ea495e12a930d96cdea0ccd3431de72
  • libcurl-7.61.1-34.el8.tuxcare.els11.i686.rpm
    sha:bdcce77497525df9c2eee3d302261cefb1e894bfc6e97d1b340a12ae3b5074d1
  • libcurl-7.61.1-34.el8.tuxcare.els11.x86_64.rpm
    sha:566edfdcec62fca3816511c394e85a653a2a86169d3752813e456199fab48429
  • libcurl-devel-7.61.1-34.el8.tuxcare.els11.i686.rpm
    sha:9d4bf95d1778569588fbb7f7134d8f4b13e7ff57ee86baa1aed8178d72953b6a
  • libcurl-devel-7.61.1-34.el8.tuxcare.els11.x86_64.rpm
    sha:f74eea54e49fa732a59c37f4d351ed70257c73ff642d3cd28790ca2456fad973
  • libcurl-minimal-7.61.1-34.el8.tuxcare.els11.i686.rpm
    sha:4c2051269d7bb2c42eaa839cc379cde3a1b902977704a9e3cd61bab87afae800
  • libcurl-minimal-7.61.1-34.el8.tuxcare.els11.x86_64.rpm
    sha:31350d4496c3dcea65d838274c3c5eb66ea7c259fe6270ad1fb419cf96fc797b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.