Release date:
2026-09-15 15:54:22 UTC
Description:
- CVE-2026-13608: fail the LDAP connection with CURLE_LOGIN_DENIED when the SASL
negotiation ends without a completed mechanism instead of treating it as
authenticated
- CVE-2026-18924: make HTTP/2 server push transfers inherit the share from the
parent handle, preventing a use-after-free during cleanup
Updated packages:
-
curl-8.3.0-1.amzn2.0.12.tuxcare.els7.x86_64.rpm
sha:dcc8ecdbd3eef07e0f71a20b67c5fe2e4b9e68aca90d2e1602a87ef7764ea08c
-
libcurl-8.3.0-1.amzn2.0.12.tuxcare.els7.i686.rpm
sha:f5b62cae356c3fe6b57c3c781acff531c370309d69cc7d5a19daf6d4b9ae229c
-
libcurl-8.3.0-1.amzn2.0.12.tuxcare.els7.x86_64.rpm
sha:20f85bcbee8bac8ce1bc51e50c37e8f4e4f7f184f21f7ce8a2eebdf790153181
-
libcurl-devel-8.3.0-1.amzn2.0.12.tuxcare.els7.x86_64.rpm
sha:5b92af70fbb2fabc37844a775593f99e82687539764f18650738f068ca7bd3d6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.