Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-55439

Опубликовано: 17 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-55439: curl security update (IMPORTANT)

[7.76.1-40.el9_8.5]

  • fix missing %patch macros for Patch46 and Patch47

[7.76.1-40.el9_8.4]

  • fix HTTP Negotiate connection reuse auth bypass (CVE-2026-1965)
  • fix OAuth2 bearer token leak via redirect and netrc (CVE-2026-3783)
  • tests: disable flaky test 1206 on x86_64 (FTP PORT timeout under valgrind)

[7.76.1-40.3]

  • tests: disable flaky tests 3000, 3001 on i686 (stunnel startup race)

[7.76.1-40.1]

  • fix SSH host key mismatch on type difference (CVE-2026-9547)
  • fix TLS/STARTTLS connection reuse vulnerability (CVE-2026-8286)

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

curl

7.76.1-40.el9_8.5

curl-minimal

7.76.1-40.el9_8.5

libcurl

7.76.1-40.el9_8.5

libcurl-devel

7.76.1-40.el9_8.5

libcurl-minimal

7.76.1-40.el9_8.5

Oracle Linux x86_64

curl

7.76.1-40.el9_8.5

curl-minimal

7.76.1-40.el9_8.5

libcurl

7.76.1-40.el9_8.5

libcurl-devel

7.76.1-40.el9_8.5

libcurl-minimal

7.76.1-40.el9_8.5

Связанные уязвимости

rocky
29 дней назад

Important: curl security update

oracle-oval
29 дней назад

ELSA-2026-55450: curl security update (IMPORTANT)

suse-cvrf
6 месяцев назад

Security update for curl

suse-cvrf
6 месяцев назад

Security update for curl

suse-cvrf
6 месяцев назад

Security update for curl