[CLSA-2026:1791189115] curl: Fix of 12 CVEs
Type:
security
Severity:
None
Release date:
2026-10-05 08:32:05 UTC
Description:
- Rebase onto the vendor's 8.3.0-1.amzn2.0.13 sources, which add fixes for CVE-2026-80230 (openssl: accept a missing server certificate only when public key pinning was not requested) and CVE-2026-8924 (cookie handling) - CVE-2026-13608 is now fixed by the vendor; the vendor's version of CVE-2026-13608.patch was taken and the TuxCare duplicate is dropped - CVE-2026-12064 is now fixed by the vendor; the vendor's version of CVE-2026-12064.patch was taken and the TuxCare duplicate is dropped - CVE-2026-8286 is now fixed by the vendor; the vendor's version of CVE-2026-8286.patch was taken and the TuxCare duplicate is dropped - Retained the TuxCare fixes for CVE-2025-0167, CVE-2026-6276, CVE-2026-5773, CVE-2026-10536, CVE-2026-8927, CVE-2026-8932 and CVE-2026-18924
Updated packages:
  • curl-8.3.0-1.amzn2.0.13.tuxcare.els1.aarch64.rpm
    sha:28b5e1c83445286fa9bb235ba7aa093dfb1e04397a652f4f997b2c27a99aaf2f
  • curl-8.3.0-1.amzn2.0.13.tuxcare.els1.i686.rpm
    sha:9350dddcdbbc3d22b31497df7dc8517e0f78edbc1dd8dcb142165f10db3ceae5
  • curl-8.3.0-1.amzn2.0.13.tuxcare.els1.x86_64.rpm
    sha:aaa800c4adfb7e35122f5a7fdf99ae676abb93f216b5020c696ac4a341447b7b
  • libcurl-8.3.0-1.amzn2.0.13.tuxcare.els1.aarch64.rpm
    sha:5ba539883e235f9fc7bb6cd58cab675dc2683b702ed5b79f2d02408ce4fc0f1d
  • libcurl-8.3.0-1.amzn2.0.13.tuxcare.els1.i686.rpm
    sha:abbd1fbe83f13a8c1777e4ea6f6281db7f5ae56d1583bbdf96d7936bfb505218
  • libcurl-8.3.0-1.amzn2.0.13.tuxcare.els1.x86_64.rpm
    sha:20b7274df30d3dc6d04c6885ab9b80642d36cba16a122195d46e5ee693f34e95
  • libcurl-devel-8.3.0-1.amzn2.0.13.tuxcare.els1.aarch64.rpm
    sha:054cba351ad2c4e870af6296edffdfbad78f13791b3182a101cbecbc85cd79b0
  • libcurl-devel-8.3.0-1.amzn2.0.13.tuxcare.els1.i686.rpm
    sha:42a2c18e573b1d7b1a782af6a9a325d9267298a1e273540ab10413ce0aa1fb42
  • libcurl-devel-8.3.0-1.amzn2.0.13.tuxcare.els1.x86_64.rpm
    sha:491c212967ad8e0f98f5b607d944742e45fc10f21e5b7c3548788f673df50e2e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.