Описание
ELSA-2026-57462: curl security, bug fix, and enhancement update (IMPORTANT)
[7.61.1-34.el8_10.13]
- fix TLS/STARTTLS connection reuse vulnerability (CVE-2026-8286)
[7.61.1-34.el8_10.12]
- NTLM: use HTTP/1.0 instead of HTTP/1.1 for compatibility (RHEL-171912)
Обновленные пакеты
Oracle Linux 8
Oracle Linux aarch64
curl
7.61.1-34.el8_10.13
libcurl
7.61.1-34.el8_10.13
libcurl-devel
7.61.1-34.el8_10.13
libcurl-minimal
7.61.1-34.el8_10.13
Oracle Linux x86_64
curl
7.61.1-34.el8_10.13
libcurl
7.61.1-34.el8_10.13
libcurl-devel
7.61.1-34.el8_10.13
libcurl-minimal
7.61.1-34.el8_10.13
Связанные CVE
Связанные уязвимости
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.
A vulnerability exists where a new transfer that uses STARTTLS to upgr ...