[CLSA-2026:1779358660] curl: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-05-21 14:43:49 UTC
Description:
- CVE-2026-5773: wrong reuse of SMB connection; disable connection reuse for SMB(S) so a subsequent transfer cannot wrongfully reuse a pooled connection to a different share - CVE-2026-6276: clear stale custom-Host cookiehost between requests on the same easy handle (cookie leak across origins)
Updated packages:
  • curl-7.76.1-31.el9_2.1.tuxcare.els11.x86_64.rpm
    sha:e38848f331a0f620216d73955e071b9d1d9e033069373cde05cd52ed31129bc9
  • curl-minimal-7.76.1-31.el9_2.1.tuxcare.els11.x86_64.rpm
    sha:9691528f3d976d44e31cbec7acdbd3cc7f67138c4bda57502e14b9b39452f4e4
  • libcurl-7.76.1-31.el9_2.1.tuxcare.els11.i686.rpm
    sha:04d50ccf369ab000924f2c1e987d8893b42ea0c36386881c77e488ee24a7c2f5
  • libcurl-7.76.1-31.el9_2.1.tuxcare.els11.x86_64.rpm
    sha:b7a2b91f9426a5d9bfe86ed2089f1010270e7f01102a46884d73b9c88457869c
  • libcurl-devel-7.76.1-31.el9_2.1.tuxcare.els11.i686.rpm
    sha:36b33bde9510b8e9ed82b9b1ee68fba7a9a2c6b90dc3a1448a14bd32d7a41711
  • libcurl-devel-7.76.1-31.el9_2.1.tuxcare.els11.x86_64.rpm
    sha:f7d1b665cf78cecd1bf5c8a90457496dd1314da29871bff68656016f9b8de3bd
  • libcurl-minimal-7.76.1-31.el9_2.1.tuxcare.els11.i686.rpm
    sha:f5f2a7e6d17fffbeeb8f88f729a986a2b07d6bc5f9eb6ca4f98f5b793826d65d
  • libcurl-minimal-7.76.1-31.el9_2.1.tuxcare.els11.x86_64.rpm
    sha:c4a9817647e113de2b379264ae36ea886d6aa98567d9eecc3ed04e385283a47d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.