[CLSA-2026:1789566546] Fix CVE(s): CVE-2026-18924
Type:
security
Severity:
Important
Release date:
2026-09-16 13:49:17 UTC
Description:
* SECURITY UPDATE: use-after-free when an HTTP/2 server push transfer is cleaned up while the parent handle uses a shared connection cache - debian/patches/CVE-2026-18924.patch: use-after-free when an HTTP/2 server push transfer is cleaned up while the parent handle uses a shared connection cache - CVE-2026-18924
CVEs fixed:
Updated packages:
  • curl_7.64.0-4+deb10u9+tuxcare.els6_amd64.deb
    sha:bb457e94eeaa54b04bbeeaee06b87a3343c2bc9e
  • libcurl3-gnutls_7.64.0-4+deb10u9+tuxcare.els6_amd64.deb
    sha:6c222e343aada9bd653d4b30bca35d583e19232f
  • libcurl3-nss_7.64.0-4+deb10u9+tuxcare.els6_amd64.deb
    sha:ed3a63bda93323e59f270f5043b20be2734c844b
  • libcurl4_7.64.0-4+deb10u9+tuxcare.els6_amd64.deb
    sha:38d2871ee325602d7522c1f6ee10957c00711c7f
  • libcurl4-doc_7.64.0-4+deb10u9+tuxcare.els6_all.deb
    sha:1e2a3044bd41ba903dc90d1dc7389e7b6d14ac2a
  • libcurl4-gnutls-dev_7.64.0-4+deb10u9+tuxcare.els6_amd64.deb
    sha:b63121d9b3fbd68d8ffc022784614d8e0dabbc3a
  • libcurl4-nss-dev_7.64.0-4+deb10u9+tuxcare.els6_amd64.deb
    sha:c6190131b44275725cd7fb988a2ee9c7411fb49d
  • libcurl4-openssl-dev_7.64.0-4+deb10u9+tuxcare.els6_amd64.deb
    sha:693f66054b55d6eafa6531d9c7be09afdc4d64f9
  • curl_7.64.0-4+deb10u9+tuxcare.els6_arm64.deb
    sha:1752aad4957698ee3c2aa1185c84eadd99de3f3b
  • libcurl3-gnutls_7.64.0-4+deb10u9+tuxcare.els6_arm64.deb
    sha:401d9e01afa46c61984cc8081bb448c5106b4e60
  • libcurl3-nss_7.64.0-4+deb10u9+tuxcare.els6_arm64.deb
    sha:847b2d037a603ba67a14709695ebebc3ddf2dbd2
  • libcurl4_7.64.0-4+deb10u9+tuxcare.els6_arm64.deb
    sha:21a91e1627355e1ed58ba1ea880e2b1b137afcc0
  • libcurl4-gnutls-dev_7.64.0-4+deb10u9+tuxcare.els6_arm64.deb
    sha:f2cf87647051c754aed20843f1462ef7aa1c509c
  • libcurl4-nss-dev_7.64.0-4+deb10u9+tuxcare.els6_arm64.deb
    sha:8afd4a4f9eb01d695dd299531062151011f4519a
  • libcurl4-openssl-dev_7.64.0-4+deb10u9+tuxcare.els6_arm64.deb
    sha:4eebd1dc0072cd9115267493e7520db457df7700
  • curl_7.64.0-4+deb10u9+tuxcare.els6_armel.deb
    sha:eb24e1f7a0cfe85542dde14f0c3c9c5c77684173
  • libcurl3-gnutls_7.64.0-4+deb10u9+tuxcare.els6_armel.deb
    sha:ce71da5a997d1aedb3cc1c2fd78c859c78fea67c
  • libcurl3-nss_7.64.0-4+deb10u9+tuxcare.els6_armel.deb
    sha:5709df88b59de87ad164aa1e5f7df6960546554c
  • libcurl4_7.64.0-4+deb10u9+tuxcare.els6_armel.deb
    sha:087e4571bd048d97a4f1e9e4d36b3611cbc65c0f
  • libcurl4-gnutls-dev_7.64.0-4+deb10u9+tuxcare.els6_armel.deb
    sha:4c1d42852dd6b73b756ef0349642ce22554d6da4
  • libcurl4-nss-dev_7.64.0-4+deb10u9+tuxcare.els6_armel.deb
    sha:733c9d740765da5656d50b7aa38de166a97c742d
  • libcurl4-openssl-dev_7.64.0-4+deb10u9+tuxcare.els6_armel.deb
    sha:2764f1ec8742d5f0cfb8c1dfaf248511cc7fc98d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.