[CLSA-2026:1773153207] curl: Fix of 2 CVEs
Type:
security
Severity:
Low
Release date:
2026-03-10 14:33:31 UTC
Description:
- CVE-2025-15079: libssh global known_hosts file override - CVE-2025-14524: bearer token leak on cross-protocol redirect
Updated packages:
  • curl-7.61.1-34.el8.tuxcare.els4.x86_64.rpm
    sha:bf004846119126a881fc4c31375044a06977687816cfca1cdd6d53779ea55b2c
  • curl-minimal-7.61.1-34.el8.tuxcare.els4.x86_64.rpm
    sha:554af245ea2b6502eb1982d366dbb039bc74f7f58a6065a75327a37fc724ece4
  • libcurl-7.61.1-34.el8.tuxcare.els4.i686.rpm
    sha:e74a52302a2540eb416f96dddbf036fc10e79c309b81a339b7594c133e37f7e3
  • libcurl-7.61.1-34.el8.tuxcare.els4.x86_64.rpm
    sha:b9ba9cfeaa11340a9d5a60c93b43ae19a533562adff0a2b82bd5d392faa0abd0
  • libcurl-devel-7.61.1-34.el8.tuxcare.els4.i686.rpm
    sha:cdaeb583aa165f5f4abed2421e103afb969c04d931b38655c033a63aa111d9db
  • libcurl-devel-7.61.1-34.el8.tuxcare.els4.x86_64.rpm
    sha:716fd09b0e279253f8672feeadbe929a377d89626090a508e03f76cb6553900d
  • libcurl-minimal-7.61.1-34.el8.tuxcare.els4.i686.rpm
    sha:2b3cf2bb7fb08f0940368be1c47614327aa598a9a3d27c13a1e488eb87c269bc
  • libcurl-minimal-7.61.1-34.el8.tuxcare.els4.x86_64.rpm
    sha:51e89061f618569bf56209cf2594d730fbd33f87cf46f770aae890d66fa13f3a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.