[CLSA-2026:1786446944] Fix CVE(s): CVE-2026-8932
Type:
security
Severity:
Important
Release date:
2026-08-11 11:16:04 UTC
Description:
* SECURITY UPDATE: mTLS connection reuse with mismatched client key config - debian/patches/CVE-2026-8932.patch: promote cert_type, key, key_type and key_passwd into ssl_primary_config so connection reuse and the TLS session cache compare the full client credential set in lib/urldata.h, lib/url.c, lib/vtls/vtls.c and the TLS backends - debian/patches/CVE-2026-8932-tests.patch: add test3303 exercising conn-reuse matching on the mTLS key, cert_type, key_type and key_passwd fields. - CVE-2026-8932
CVEs fixed:
Updated packages:
  • curl_7.68.0-1ubuntu2.25+tuxcare.els4_amd64.deb
    sha:c42981b8fc84b23b2b75ea4eca3b6e16f55672eb
  • libcurl3-gnutls_7.68.0-1ubuntu2.25+tuxcare.els4_amd64.deb
    sha:558113a4353ffc05f858046ac659e1736d4c77c8
  • libcurl3-nss_7.68.0-1ubuntu2.25+tuxcare.els4_amd64.deb
    sha:ecd589f1ae02cd0ed80de27bc8f1925cb782b4d9
  • libcurl4_7.68.0-1ubuntu2.25+tuxcare.els4_amd64.deb
    sha:c4601c6c7a4d90fa605c99d09a277b2d0682ac18
  • libcurl4-doc_7.68.0-1ubuntu2.25+tuxcare.els4_all.deb
    sha:6b2f1afb66fbb43386066104c32466e52a751880
  • libcurl4-gnutls-dev_7.68.0-1ubuntu2.25+tuxcare.els4_amd64.deb
    sha:4449e41468a020c63d82fa3030133dc142edc0a0
  • libcurl4-nss-dev_7.68.0-1ubuntu2.25+tuxcare.els4_amd64.deb
    sha:370acab1814520a37edd849f60f6382c227bca35
  • libcurl4-openssl-dev_7.68.0-1ubuntu2.25+tuxcare.els4_amd64.deb
    sha:661ff7b590b20c90615ab73dfd4315d248910cf4
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.