Release date:
2026-08-06 09:04:22 UTC
Description:
* SECURITY UPDATE: connection reuse ignored client-certificate config
- debian/patches/CVE-2026-8932.patch: promote the client certificate
type, private key, key type and key password into ssl_primary_config
so the connection-reuse and session-cache match checks cover the full
mTLS client credential, in lib/urldata.h, lib/url.c, lib/vtls/vtls.c
and the TLS/ldap/ssh consumers, so a reused connection cannot inherit
a different client credential.
- CVE-2026-8932
Updated packages:
-
curl_7.58.0-2ubuntu3.24+tuxcare.els13_amd64.deb
sha:02b98360f5ab2bcd642d57447503cf2aa5a3b8fb
-
libcurl3-gnutls_7.58.0-2ubuntu3.24+tuxcare.els13_amd64.deb
sha:7daddab3c80a2357e4910f2f853ea630f048049a
-
libcurl3-nss_7.58.0-2ubuntu3.24+tuxcare.els13_amd64.deb
sha:3af443309b74c3e2b2c498e9e5e2f5642c542d25
-
libcurl4_7.58.0-2ubuntu3.24+tuxcare.els13_amd64.deb
sha:4bb1898628a5d8c1cefff9271ee3c28be6532c39
-
libcurl4-doc_7.58.0-2ubuntu3.24+tuxcare.els13_all.deb
sha:05b69b2f91d7d3c04fe9b0e739c27a60b9ae97b6
-
libcurl4-gnutls-dev_7.58.0-2ubuntu3.24+tuxcare.els13_amd64.deb
sha:bb865675ddeeda076574073a2a0877fe42bfe393
-
libcurl4-nss-dev_7.58.0-2ubuntu3.24+tuxcare.els13_amd64.deb
sha:7e3484fac2e0cdb2008be3af846d4774481c76a6
-
libcurl4-openssl-dev_7.58.0-2ubuntu3.24+tuxcare.els13_amd64.deb
sha:8db017e2702089493ed6eb8966df23d86ffa7a94
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.