Release date:
2026-08-11 11:16:04 UTC
Description:
* SECURITY UPDATE: mTLS connection reuse with mismatched client key config
- debian/patches/CVE-2026-8932.patch: promote cert_type, key, key_type and
key_passwd into ssl_primary_config so connection reuse and the TLS
session cache compare the full client credential set in lib/urldata.h,
lib/url.c, lib/vtls/vtls.c and the TLS backends
- debian/patches/CVE-2026-8932-tests.patch: add test3303 exercising
conn-reuse matching on the mTLS key, cert_type, key_type and key_passwd
fields.
- CVE-2026-8932
Updated packages:
-
curl_7.68.0-1ubuntu2.25+tuxcare.els4_amd64.deb
sha:c42981b8fc84b23b2b75ea4eca3b6e16f55672eb
-
libcurl3-gnutls_7.68.0-1ubuntu2.25+tuxcare.els4_amd64.deb
sha:558113a4353ffc05f858046ac659e1736d4c77c8
-
libcurl3-nss_7.68.0-1ubuntu2.25+tuxcare.els4_amd64.deb
sha:ecd589f1ae02cd0ed80de27bc8f1925cb782b4d9
-
libcurl4_7.68.0-1ubuntu2.25+tuxcare.els4_amd64.deb
sha:c4601c6c7a4d90fa605c99d09a277b2d0682ac18
-
libcurl4-doc_7.68.0-1ubuntu2.25+tuxcare.els4_all.deb
sha:6b2f1afb66fbb43386066104c32466e52a751880
-
libcurl4-gnutls-dev_7.68.0-1ubuntu2.25+tuxcare.els4_amd64.deb
sha:4449e41468a020c63d82fa3030133dc142edc0a0
-
libcurl4-nss-dev_7.68.0-1ubuntu2.25+tuxcare.els4_amd64.deb
sha:370acab1814520a37edd849f60f6382c227bca35
-
libcurl4-openssl-dev_7.68.0-1ubuntu2.25+tuxcare.els4_amd64.deb
sha:661ff7b590b20c90615ab73dfd4315d248910cf4
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.