Release date:
2026-03-10 16:45:29 UTC
Description:
* SECURITY UPDATE: acceptance of hosts not listed in specified known_hosts
file during SSH-based transfers
- debian/patches/CVE-2025-15079.patch: Set both knownhosts options to same
file and fix surprises caused by libssh exposing separate KNOWNHOSTS and
GLOBAL_KNOWNHOSTS options.
- CVE-2025-15079
* Regenerate Server-localhost-lastSAN-sv test certificate with SHA-256
- debian/patches/regenerate-lastSAN-cert-sha256.patch: Fix "ca md too weak"
error with OpenSSL 1.1.1+ by replacing SHA-1 signed certificate with
SHA-256. Also fixes Makefile.am bug for lastSAN target.
* Update failed test
- debian/patches/26_CVE-2021-22876.patch: Update test to avoid using
unsupported commands
* Update failed test
- debian/patches/fix-test323-errorcode.patch: two valid error codes now
* Disable some tests
- debian/rules: add option to disable tests marked as flaky, fail the
build if any test fails
- debian/patches/add-flaky-to-test1592.patch: mark test1592 as flaky
- debian/patches/disable-nss-failing-tests.patch: libnsspem.so is not
available on Debian 10
* Remove unsupported test:
- debian/patches/test8-verify-that-ctrl-byte-cookies-are-ignored.patch:
no ctrl-byte-cookies are supported
Updated packages:
-
curl_7.64.0-4+deb10u9+tuxcare.els2_amd64.deb
sha:89851431a7d5b5a442403649d2976f1e7d002373
-
libcurl3-gnutls_7.64.0-4+deb10u9+tuxcare.els2_amd64.deb
sha:8cefbd9cd4ec628b2d29251391d6d07221b6d101
-
libcurl3-nss_7.64.0-4+deb10u9+tuxcare.els2_amd64.deb
sha:d7945a7065efdf890c72280f3c15d03d4dcffd95
-
libcurl4_7.64.0-4+deb10u9+tuxcare.els2_amd64.deb
sha:6949ad359e25dbce4975d35e2614950b785e1810
-
libcurl4-doc_7.64.0-4+deb10u9+tuxcare.els2_all.deb
sha:84b3c7382e52bdf7b4238fcebd34e72b6c2edda5
-
libcurl4-gnutls-dev_7.64.0-4+deb10u9+tuxcare.els2_amd64.deb
sha:500de9ca945078b0fddf08a1cf4b6d8f1265ed9b
-
libcurl4-nss-dev_7.64.0-4+deb10u9+tuxcare.els2_amd64.deb
sha:1facfd0b0c276b9fa5b6f75eec5ff4a04de262a7
-
libcurl4-openssl-dev_7.64.0-4+deb10u9+tuxcare.els2_amd64.deb
sha:e0a7ed926796b4bee43de390ebbe3351458c0bc7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.