Release date:
2026-09-20 10:26:40 UTC
Description:
- CVE-2026-18924: use-after-free in the cleanup of HTTP/2 server push
transfers, because a pushed transfer did not inherit the parent handle's
share and could therefore outlive a shared connection
- CVE-2026-80230: public key pinning was not enforced when the server
presented no certificate and both peer and host verification were
disabled, so an unauthenticated connection succeeded where it should have
been rejected
- CVE-2026-82209: a cookie whose Domain attribute exactly matched a public
suffix was stored with wildcard domain scope instead of being coerced to
host-only, so it was sent to arbitrary sibling subdomains under that
public suffix
Updated packages:
-
curl-7.61.1-34.el8.tuxcare.els12.x86_64.rpm
sha:f0d56441558bff2f24149d44945ad3e707442e5758d05c0320195de2afd3d781
-
curl-minimal-7.61.1-34.el8.tuxcare.els12.x86_64.rpm
sha:49fcf20fac4144d85629a0fc6e29998d087ae10e7ccdf94c092d839d75bcc225
-
libcurl-7.61.1-34.el8.tuxcare.els12.i686.rpm
sha:9c737c59f87663fcb8be49256ab8a1221f1bcd452f397155d67dd94f90b9eaed
-
libcurl-7.61.1-34.el8.tuxcare.els12.x86_64.rpm
sha:e8ca40b2bb85ab62393ea33fa9ab11b58f0b182ba8aa12f3771ec94996891b65
-
libcurl-devel-7.61.1-34.el8.tuxcare.els12.i686.rpm
sha:f42c379581b7acb36e18961c9e29c8d3b709ab7c632861baca1fabf6a62078a5
-
libcurl-devel-7.61.1-34.el8.tuxcare.els12.x86_64.rpm
sha:13cab618f5d9a0c757c6e7a36fe0311687674ce56b203353ba3394a5dca8e73a
-
libcurl-minimal-7.61.1-34.el8.tuxcare.els12.i686.rpm
sha:2d50942283094afc0bc154e3ea3dcd4399a0169c5660336a109f3c2e5c510c79
-
libcurl-minimal-7.61.1-34.el8.tuxcare.els12.x86_64.rpm
sha:9220559856350ad55595640b89c1f3f012e80fae629d8704bb053ddba0088430
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.