[CLSA-2026:1773161124] Fix CVE(s): CVE-2021-22876, CVE-2025-15079
Type:
security
Severity:
Low
Release date:
2026-03-10 16:45:29 UTC
Description:
* SECURITY UPDATE: acceptance of hosts not listed in specified known_hosts file during SSH-based transfers - debian/patches/CVE-2025-15079.patch: Set both knownhosts options to same file and fix surprises caused by libssh exposing separate KNOWNHOSTS and GLOBAL_KNOWNHOSTS options. - CVE-2025-15079 * Regenerate Server-localhost-lastSAN-sv test certificate with SHA-256 - debian/patches/regenerate-lastSAN-cert-sha256.patch: Fix "ca md too weak" error with OpenSSL 1.1.1+ by replacing SHA-1 signed certificate with SHA-256. Also fixes Makefile.am bug for lastSAN target. * Update failed test - debian/patches/26_CVE-2021-22876.patch: Update test to avoid using unsupported commands * Update failed test - debian/patches/fix-test323-errorcode.patch: two valid error codes now * Disable some tests - debian/rules: add option to disable tests marked as flaky, fail the build if any test fails - debian/patches/add-flaky-to-test1592.patch: mark test1592 as flaky - debian/patches/disable-nss-failing-tests.patch: libnsspem.so is not available on Debian 10 * Remove unsupported test: - debian/patches/test8-verify-that-ctrl-byte-cookies-are-ignored.patch: no ctrl-byte-cookies are supported
Updated packages:
  • curl_7.64.0-4+deb10u9+tuxcare.els2_amd64.deb
    sha:89851431a7d5b5a442403649d2976f1e7d002373
  • libcurl3-gnutls_7.64.0-4+deb10u9+tuxcare.els2_amd64.deb
    sha:8cefbd9cd4ec628b2d29251391d6d07221b6d101
  • libcurl3-nss_7.64.0-4+deb10u9+tuxcare.els2_amd64.deb
    sha:d7945a7065efdf890c72280f3c15d03d4dcffd95
  • libcurl4_7.64.0-4+deb10u9+tuxcare.els2_amd64.deb
    sha:6949ad359e25dbce4975d35e2614950b785e1810
  • libcurl4-doc_7.64.0-4+deb10u9+tuxcare.els2_all.deb
    sha:84b3c7382e52bdf7b4238fcebd34e72b6c2edda5
  • libcurl4-gnutls-dev_7.64.0-4+deb10u9+tuxcare.els2_amd64.deb
    sha:500de9ca945078b0fddf08a1cf4b6d8f1265ed9b
  • libcurl4-nss-dev_7.64.0-4+deb10u9+tuxcare.els2_amd64.deb
    sha:1facfd0b0c276b9fa5b6f75eec5ff4a04de262a7
  • libcurl4-openssl-dev_7.64.0-4+deb10u9+tuxcare.els2_amd64.deb
    sha:e0a7ed926796b4bee43de390ebbe3351458c0bc7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.