[CLSA-2026:1789899988] curl: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2026-09-20 10:26:40 UTC
Description:
- CVE-2026-18924: use-after-free in the cleanup of HTTP/2 server push transfers, because a pushed transfer did not inherit the parent handle's share and could therefore outlive a shared connection - CVE-2026-80230: public key pinning was not enforced when the server presented no certificate and both peer and host verification were disabled, so an unauthenticated connection succeeded where it should have been rejected - CVE-2026-82209: a cookie whose Domain attribute exactly matched a public suffix was stored with wildcard domain scope instead of being coerced to host-only, so it was sent to arbitrary sibling subdomains under that public suffix
Updated packages:
  • curl-7.61.1-34.el8.tuxcare.els12.x86_64.rpm
    sha:f0d56441558bff2f24149d44945ad3e707442e5758d05c0320195de2afd3d781
  • curl-minimal-7.61.1-34.el8.tuxcare.els12.x86_64.rpm
    sha:49fcf20fac4144d85629a0fc6e29998d087ae10e7ccdf94c092d839d75bcc225
  • libcurl-7.61.1-34.el8.tuxcare.els12.i686.rpm
    sha:9c737c59f87663fcb8be49256ab8a1221f1bcd452f397155d67dd94f90b9eaed
  • libcurl-7.61.1-34.el8.tuxcare.els12.x86_64.rpm
    sha:e8ca40b2bb85ab62393ea33fa9ab11b58f0b182ba8aa12f3771ec94996891b65
  • libcurl-devel-7.61.1-34.el8.tuxcare.els12.i686.rpm
    sha:f42c379581b7acb36e18961c9e29c8d3b709ab7c632861baca1fabf6a62078a5
  • libcurl-devel-7.61.1-34.el8.tuxcare.els12.x86_64.rpm
    sha:13cab618f5d9a0c757c6e7a36fe0311687674ce56b203353ba3394a5dca8e73a
  • libcurl-minimal-7.61.1-34.el8.tuxcare.els12.i686.rpm
    sha:2d50942283094afc0bc154e3ea3dcd4399a0169c5660336a109f3c2e5c510c79
  • libcurl-minimal-7.61.1-34.el8.tuxcare.els12.x86_64.rpm
    sha:9220559856350ad55595640b89c1f3f012e80fae629d8704bb053ddba0088430
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.