Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:57462

Опубликовано: 21 авг. 2026
Источник: rocky
Оценка: Important

Описание

Important: curl security, bug fix, and enhancement update

The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.

Security Fix(es):

  • curl: curl: Insecure connection establishment due to TLS configuration mismatch (CVE-2026-8286)

Bug Fix(es) and Enhancement(s):

  • Regression of Rocky Linux-73788. The .9 revision appears to have broken the logic that forces NTLM to use HTTP/1.1. (JIRA:Rocky Linux-171912)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
curlaarch6434.el8_10.13curl-7.61.1-34.el8_10.13.aarch64.rpm
libcurlaarch6434.el8_10.13libcurl-7.61.1-34.el8_10.13.aarch64.rpm
libcurl-develaarch6434.el8_10.13libcurl-devel-7.61.1-34.el8_10.13.aarch64.rpm
libcurl-minimalaarch6434.el8_10.13libcurl-minimal-7.61.1-34.el8_10.13.aarch64.rpm
curlx86_6434.el8_10.13curl-7.61.1-34.el8_10.13.x86_64.rpm
libcurli68634.el8_10.13libcurl-7.61.1-34.el8_10.13.i686.rpm
libcurlx86_6434.el8_10.13libcurl-7.61.1-34.el8_10.13.x86_64.rpm
libcurl-develi68634.el8_10.13libcurl-devel-7.61.1-34.el8_10.13.i686.rpm
libcurl-develx86_6434.el8_10.13libcurl-devel-7.61.1-34.el8_10.13.x86_64.rpm
libcurl-minimali68634.el8_10.13libcurl-minimal-7.61.1-34.el8_10.13.i686.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 8.1
ubuntu
2 месяца назад

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

CVSS3: 8.1
redhat
2 месяца назад

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

CVSS3: 8.1
nvd
2 месяца назад

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

CVSS3: 8.1
msrc
2 месяца назад

wrong STARTTLS connection reuse

CVSS3: 8.1
debian
2 месяца назад

A vulnerability exists where a new transfer that uses STARTTLS to upgr ...