[CLSA-2026:1773135327] curl: Fix of 2 CVEs
Type:
security
Severity:
Low
Release date:
2026-03-10 09:35:32 UTC
Description:
- CVE-2025-14524: prevent bearer token leak on cross-protocol redirect - CVE-2025-15079: set both SSH knownhosts options to the same file to prevent libssh global known_hosts override
Updated packages:
  • curl-7.61.1-22.el8.tuxcare.els16.x86_64.rpm
    sha:f73bdd1aad41e266749e71f0c9080f39114fd9dabb089fa5f2a563f90b3fd38f
  • curl-minimal-7.61.1-22.el8.tuxcare.els16.x86_64.rpm
    sha:fb981370cfda1a3519cae7c452e7e0c23f05f6387aa5844e84aab45f2cc4f6fc
  • libcurl-7.61.1-22.el8.tuxcare.els16.i686.rpm
    sha:d9fa822f115f8e3df395ff7f7efab82d9abe7317358820748d66d974298fe357
  • libcurl-7.61.1-22.el8.tuxcare.els16.x86_64.rpm
    sha:da9f4b79f778edfd476968994fcdf1d032db2d35c982d0e25104b378fa6f8dba
  • libcurl-devel-7.61.1-22.el8.tuxcare.els16.i686.rpm
    sha:8792a365079112bc678f513a74ec3d7a0e0940908840d935efe62f051ecb08a4
  • libcurl-devel-7.61.1-22.el8.tuxcare.els16.x86_64.rpm
    sha:a4838244a4174eedf3a682608757a0936afd35df12fb956b82faaba620aaba3c
  • libcurl-minimal-7.61.1-22.el8.tuxcare.els16.i686.rpm
    sha:c136597c9aba86b3db14da430e374f4bed0029a1dae9b543e5f446ed7d63044e
  • libcurl-minimal-7.61.1-22.el8.tuxcare.els16.x86_64.rpm
    sha:42eb5b7d6808c268842712f53ef04255e1c3ddfbc6fd7cdd4f2920ae0436d99c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.