[CLSA-2026:1779357790] curl: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-05-21 14:36:58 UTC
Description:
- CVE-2026-5773: wrong reuse of SMB connection; disable connection reuse for SMB(S) so a subsequent transfer cannot wrongfully reuse a pooled connection to a different share - CVE-2026-6276: clear stale custom-Host cookiehost between requests on the same easy handle (cookie leak across origins)
Updated packages:
  • curl-7.76.1-31.el9_6.1.tuxcare.els11.x86_64.rpm
    sha:1a1ed0259e7921756bd577888d90ef9091cb328fbb5a025a04b8f48cbff54381
  • curl-minimal-7.76.1-31.el9_6.1.tuxcare.els11.x86_64.rpm
    sha:ad272054059f6ad99f46252178247659e76b7102389cdf90022ade333753b60a
  • libcurl-7.76.1-31.el9_6.1.tuxcare.els11.i686.rpm
    sha:d6ec86aa9391f0cd2cb4b2497f61eae3e9f3aa4d745bcdae6d80ac2d189a7ed7
  • libcurl-7.76.1-31.el9_6.1.tuxcare.els11.x86_64.rpm
    sha:0e39109910e0aa226e8af1bdbe3e6ea33f73237278f4683c77cb575c2b2af9a0
  • libcurl-devel-7.76.1-31.el9_6.1.tuxcare.els11.i686.rpm
    sha:df291e7917abbae2ad354280779f608aa044dd5f66dd5d52c676b7a769c9064d
  • libcurl-devel-7.76.1-31.el9_6.1.tuxcare.els11.x86_64.rpm
    sha:744fc24ebe3904f9389ebb0e50953a16fcb48ff411a5dc8a114ff6d735808811
  • libcurl-minimal-7.76.1-31.el9_6.1.tuxcare.els11.i686.rpm
    sha:457294557d774f9a2db111dc6c53a431f16b5832583e84f02da8a14a61932f3a
  • libcurl-minimal-7.76.1-31.el9_6.1.tuxcare.els11.x86_64.rpm
    sha:316e8480ac8f70e2c1f5249e14f9267158ad7533dcf9712929dec7ccf4806d65
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.