Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-57462

Опубликовано: 20 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2026-57462: curl security, bug fix, and enhancement update (IMPORTANT)

[7.61.1-34.el8_10.13]

  • fix TLS/STARTTLS connection reuse vulnerability (CVE-2026-8286)

[7.61.1-34.el8_10.12]

  • NTLM: use HTTP/1.0 instead of HTTP/1.1 for compatibility (RHEL-171912)

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

curl

7.61.1-34.el8_10.13

libcurl

7.61.1-34.el8_10.13

libcurl-devel

7.61.1-34.el8_10.13

libcurl-minimal

7.61.1-34.el8_10.13

Oracle Linux x86_64

curl

7.61.1-34.el8_10.13

libcurl

7.61.1-34.el8_10.13

libcurl-devel

7.61.1-34.el8_10.13

libcurl-minimal

7.61.1-34.el8_10.13

Связанные CVE

Связанные уязвимости

CVSS3: 8.1
ubuntu
2 месяца назад

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

CVSS3: 8.1
redhat
2 месяца назад

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

CVSS3: 8.1
nvd
2 месяца назад

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

CVSS3: 8.1
msrc
2 месяца назад

wrong STARTTLS connection reuse

CVSS3: 8.1
debian
2 месяца назад

A vulnerability exists where a new transfer that uses STARTTLS to upgr ...