Release date:
2026-09-13 08:59:44 UTC
Description:
* SECURITY UPDATE: wrong reuse of SMB connection
- debian/patches/CVE-2026-5773.patch: disable connection reuse for SMB
and SMBS by closing the connection in smb_connect() in lib/smb.c.
- CVE-2026-5773
* SECURITY UPDATE: stale custom cookie host causes cookie leak
- debian/patches/CVE-2026-6276.patch: clear the remembered custom
Host: name at the start of every request in lib/http.c.
- CVE-2026-6276
* SECURITY UPDATE: wrong STARTTLS connection reuse
- debian/patches/CVE-2026-8286.patch: require a matching SSL
configuration when reusing a connection for a transfer that may
upgrade to TLS in lib/url.c.
- CVE-2026-8286
* SECURITY UPDATE: env-set cross-proxy Digest auth state leak
- debian/patches/CVE-2026-8927.patch: flush the proxy Digest state
when the proxy read from the environment changes in lib/url.c,
lib/urldata.h.
- CVE-2026-8927
* SECURITY UPDATE: incomplete mTLS config in connection reuse and TLS
session cache
- debian/patches/CVE-2026-8932.patch: include the client private key
options in the primary SSL config so connection reuse and the TLS
session cache compare them in lib/url.c, lib/urldata.h,
lib/vtls/vtls.c.
- CVE-2026-8932
Updated packages:
-
curl_7.74.0-1.3+deb11u16+tuxcare.els1_amd64.deb
sha:45e4d9eea4020113560feada2398a27372b412b4
-
libcurl3-gnutls_7.74.0-1.3+deb11u16+tuxcare.els1_amd64.deb
sha:991ebb2b2fb2a2e5ba6bf45147c3455ef4e7f574
-
libcurl3-nss_7.74.0-1.3+deb11u16+tuxcare.els1_amd64.deb
sha:1d15195046643628971bea6c81156decbf597635
-
libcurl4_7.74.0-1.3+deb11u16+tuxcare.els1_amd64.deb
sha:10ad08571e47cc71e2fbddd5f9dcd344f7c2b276
-
libcurl4-doc_7.74.0-1.3+deb11u16+tuxcare.els1_all.deb
sha:968c1631fc4fcd8602b548e60cd01f504c096522
-
libcurl4-gnutls-dev_7.74.0-1.3+deb11u16+tuxcare.els1_amd64.deb
sha:4184ae6985af12ffbae9034b9a6ba74c23991041
-
libcurl4-nss-dev_7.74.0-1.3+deb11u16+tuxcare.els1_amd64.deb
sha:34b4140029131f873a7472ba36ac04af5658d05f
-
libcurl4-openssl-dev_7.74.0-1.3+deb11u16+tuxcare.els1_amd64.deb
sha:9fd259919562ba554794ed393e4685d04fd00d24
-
curl_7.74.0-1.3+deb11u16+tuxcare.els1_arm64.deb
sha:ef47ab7b68c3ecea65cde873cbeb08496db48dbb
-
libcurl3-gnutls_7.74.0-1.3+deb11u16+tuxcare.els1_arm64.deb
sha:e62ff7dc0ceb502a56a01e057a6bd02ad3cda819
-
libcurl3-nss_7.74.0-1.3+deb11u16+tuxcare.els1_arm64.deb
sha:08f0daee42f7d7959b5e6697059453742d4814a4
-
libcurl4_7.74.0-1.3+deb11u16+tuxcare.els1_arm64.deb
sha:fea7e44de51b854f2f61146a58a4c56ae396fea8
-
libcurl4-gnutls-dev_7.74.0-1.3+deb11u16+tuxcare.els1_arm64.deb
sha:04df41b9b2441bdd82961de53b0df64d641e62d0
-
libcurl4-nss-dev_7.74.0-1.3+deb11u16+tuxcare.els1_arm64.deb
sha:f235f09867741962248a69b0ebc08176f8db06a2
-
libcurl4-openssl-dev_7.74.0-1.3+deb11u16+tuxcare.els1_arm64.deb
sha:cd040a0246f54f56da2c281b76ba8f50cb07ccb7
-
curl_7.74.0-1.3+deb11u16+tuxcare.els1_armel.deb
sha:ca0af672a99e835351300cfc2874bbc3c950a5f7
-
libcurl3-gnutls_7.74.0-1.3+deb11u16+tuxcare.els1_armel.deb
sha:20d12f08ef8f2de6078d9eb4327a96e0a3ff6e7d
-
libcurl3-nss_7.74.0-1.3+deb11u16+tuxcare.els1_armel.deb
sha:64a97522f07282408ce975046496cf260ac09f80
-
libcurl4_7.74.0-1.3+deb11u16+tuxcare.els1_armel.deb
sha:c78e1e20db11f479838b68226cc34647d1db0311
-
libcurl4-gnutls-dev_7.74.0-1.3+deb11u16+tuxcare.els1_armel.deb
sha:83c95cca1a592e5400b06e13cf3f7d2c21d2f3bf
-
libcurl4-nss-dev_7.74.0-1.3+deb11u16+tuxcare.els1_armel.deb
sha:d003599d63f44d02af1ee801b914d5607ef57f58
-
libcurl4-openssl-dev_7.74.0-1.3+deb11u16+tuxcare.els1_armel.deb
sha:970297f7c7c2d59b6fa27864d8d9bb949b28c140
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.