[CLSA-2026:1789289969] Fix of 5 CVEs
Type:
security
Severity:
Important
Release date:
2026-09-13 08:59:44 UTC
Description:
* SECURITY UPDATE: wrong reuse of SMB connection - debian/patches/CVE-2026-5773.patch: disable connection reuse for SMB and SMBS by closing the connection in smb_connect() in lib/smb.c. - CVE-2026-5773 * SECURITY UPDATE: stale custom cookie host causes cookie leak - debian/patches/CVE-2026-6276.patch: clear the remembered custom Host: name at the start of every request in lib/http.c. - CVE-2026-6276 * SECURITY UPDATE: wrong STARTTLS connection reuse - debian/patches/CVE-2026-8286.patch: require a matching SSL configuration when reusing a connection for a transfer that may upgrade to TLS in lib/url.c. - CVE-2026-8286 * SECURITY UPDATE: env-set cross-proxy Digest auth state leak - debian/patches/CVE-2026-8927.patch: flush the proxy Digest state when the proxy read from the environment changes in lib/url.c, lib/urldata.h. - CVE-2026-8927 * SECURITY UPDATE: incomplete mTLS config in connection reuse and TLS session cache - debian/patches/CVE-2026-8932.patch: include the client private key options in the primary SSL config so connection reuse and the TLS session cache compare them in lib/url.c, lib/urldata.h, lib/vtls/vtls.c. - CVE-2026-8932
Updated packages:
  • curl_7.74.0-1.3+deb11u16+tuxcare.els1_amd64.deb
    sha:45e4d9eea4020113560feada2398a27372b412b4
  • libcurl3-gnutls_7.74.0-1.3+deb11u16+tuxcare.els1_amd64.deb
    sha:991ebb2b2fb2a2e5ba6bf45147c3455ef4e7f574
  • libcurl3-nss_7.74.0-1.3+deb11u16+tuxcare.els1_amd64.deb
    sha:1d15195046643628971bea6c81156decbf597635
  • libcurl4_7.74.0-1.3+deb11u16+tuxcare.els1_amd64.deb
    sha:10ad08571e47cc71e2fbddd5f9dcd344f7c2b276
  • libcurl4-doc_7.74.0-1.3+deb11u16+tuxcare.els1_all.deb
    sha:968c1631fc4fcd8602b548e60cd01f504c096522
  • libcurl4-gnutls-dev_7.74.0-1.3+deb11u16+tuxcare.els1_amd64.deb
    sha:4184ae6985af12ffbae9034b9a6ba74c23991041
  • libcurl4-nss-dev_7.74.0-1.3+deb11u16+tuxcare.els1_amd64.deb
    sha:34b4140029131f873a7472ba36ac04af5658d05f
  • libcurl4-openssl-dev_7.74.0-1.3+deb11u16+tuxcare.els1_amd64.deb
    sha:9fd259919562ba554794ed393e4685d04fd00d24
  • curl_7.74.0-1.3+deb11u16+tuxcare.els1_arm64.deb
    sha:ef47ab7b68c3ecea65cde873cbeb08496db48dbb
  • libcurl3-gnutls_7.74.0-1.3+deb11u16+tuxcare.els1_arm64.deb
    sha:e62ff7dc0ceb502a56a01e057a6bd02ad3cda819
  • libcurl3-nss_7.74.0-1.3+deb11u16+tuxcare.els1_arm64.deb
    sha:08f0daee42f7d7959b5e6697059453742d4814a4
  • libcurl4_7.74.0-1.3+deb11u16+tuxcare.els1_arm64.deb
    sha:fea7e44de51b854f2f61146a58a4c56ae396fea8
  • libcurl4-gnutls-dev_7.74.0-1.3+deb11u16+tuxcare.els1_arm64.deb
    sha:04df41b9b2441bdd82961de53b0df64d641e62d0
  • libcurl4-nss-dev_7.74.0-1.3+deb11u16+tuxcare.els1_arm64.deb
    sha:f235f09867741962248a69b0ebc08176f8db06a2
  • libcurl4-openssl-dev_7.74.0-1.3+deb11u16+tuxcare.els1_arm64.deb
    sha:cd040a0246f54f56da2c281b76ba8f50cb07ccb7
  • curl_7.74.0-1.3+deb11u16+tuxcare.els1_armel.deb
    sha:ca0af672a99e835351300cfc2874bbc3c950a5f7
  • libcurl3-gnutls_7.74.0-1.3+deb11u16+tuxcare.els1_armel.deb
    sha:20d12f08ef8f2de6078d9eb4327a96e0a3ff6e7d
  • libcurl3-nss_7.74.0-1.3+deb11u16+tuxcare.els1_armel.deb
    sha:64a97522f07282408ce975046496cf260ac09f80
  • libcurl4_7.74.0-1.3+deb11u16+tuxcare.els1_armel.deb
    sha:c78e1e20db11f479838b68226cc34647d1db0311
  • libcurl4-gnutls-dev_7.74.0-1.3+deb11u16+tuxcare.els1_armel.deb
    sha:83c95cca1a592e5400b06e13cf3f7d2c21d2f3bf
  • libcurl4-nss-dev_7.74.0-1.3+deb11u16+tuxcare.els1_armel.deb
    sha:d003599d63f44d02af1ee801b914d5607ef57f58
  • libcurl4-openssl-dev_7.74.0-1.3+deb11u16+tuxcare.els1_armel.deb
    sha:970297f7c7c2d59b6fa27864d8d9bb949b28c140
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.