[ALSA-2026:69125] Important: curl security update
Type:
security
Severity:
important
Release date:
2026-09-22
Description:
The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP. Security Fix(es): * libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse (CVE-2026-8932) * curl: curl: Information disclosure via incorrect .netrc password lookup (CVE-2026-8926) * curl: libcurl: Unauthorized connection reuse due to a logical error (CVE-2026-8458) * curl: curl: Cookie injection via malicious HTTP server using super cookies (CVE-2026-8924) * curl: curl: Information disclosure via incorrect Digest authentication header reuse (CVE-2026-11856) * libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials (CVE-2026-9079) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 libcurl-devel-8.12.1-4.el10_2.6.aarch64.rpm 0b9e321b52def8c8435f0844d4b62d745a8dd40e455cb96fb5c73b3169bffed8
aarch64 libcurl-minimal-8.12.1-4.el10_2.6.aarch64.rpm 4cb721d013db197d3dc1ad65b90f6983e5b61eab93de0844e3845eaeb2074f5f
aarch64 curl-8.12.1-4.el10_2.6.aarch64.rpm be3e4907d769439a6ce7d9a5961448616a41a7163ede1cc386bbfdaa450a30c5
aarch64 libcurl-8.12.1-4.el10_2.6.aarch64.rpm df586437241ebf91ac9cb1944e140e98a71e57af51fe8a6663b77ddb97546a6f
ppc64le curl-8.12.1-4.el10_2.6.ppc64le.rpm 4cfc26b17034ccc62b989602651d659d7880b0da2cf8d943f8fc26834c0fd58f
ppc64le libcurl-minimal-8.12.1-4.el10_2.6.ppc64le.rpm 7a67281497b1f4800849f3f4e5f18d0c82e2edfb51a571030fdefe70c122119a
ppc64le libcurl-devel-8.12.1-4.el10_2.6.ppc64le.rpm cc725b6ddc1c9752a6360358d6b36133a4d565114e8e52e30b78c758b3c6a5a8
ppc64le libcurl-8.12.1-4.el10_2.6.ppc64le.rpm dafb10868f15b2eee2c8d926e583b7d962efb900d79853a11810708df940e66a
s390x libcurl-8.12.1-4.el10_2.6.s390x.rpm 0ac96599e7bfda4399f35cba8a4f714ed9d8ccfe1fab392ec01f9c73fe4f6d3d
s390x libcurl-minimal-8.12.1-4.el10_2.6.s390x.rpm 5af15e9af8fb5f5da0bf8491135b729f7c75486b37a97a5b3053ba263793227a
s390x libcurl-devel-8.12.1-4.el10_2.6.s390x.rpm 5bf526f99a36b016e8ebedfad23851a028da99ab307510bcd9b3cd8930114c31
s390x curl-8.12.1-4.el10_2.6.s390x.rpm da36327689e9c051a624bea329bea5258d62de22d78d4e75682696961008d5d1
x86_64 libcurl-8.12.1-4.el10_2.6.x86_64.rpm 1f32fc34b3456668579df3d041946d5aa11fbe44db9d2e9f10f8ba652eb3edc1
x86_64 libcurl-minimal-8.12.1-4.el10_2.6.x86_64.rpm 48b9b882642fbd746693c18da91d5c15b4943b540fad0b6cdc637ae6f637b037
x86_64 libcurl-devel-8.12.1-4.el10_2.6.x86_64.rpm 5738e1a01089c33fca250c44e15a32f1a778dde3140c71024951327d491ec2de
x86_64 curl-8.12.1-4.el10_2.6.x86_64.rpm 9063ab524df3b854e6f5182cae2ca4d6f15175851e91a56c362e87e08cee84c5
x86_64_v2 curl-8.12.1-4.el10_2.6.x86_64_v2.rpm 2930323182c8d2ee22db0a21111c67f56250589e8db3ae139619a95e1119d8e1
x86_64_v2 libcurl-8.12.1-4.el10_2.6.x86_64_v2.rpm bfb3d81c02331711c1043cd2f507d53b2e22ec151b4eb10d6e40026a97a42e5f
x86_64_v2 libcurl-minimal-8.12.1-4.el10_2.6.x86_64_v2.rpm dca951bbe13f4cc3d0ed9f49ef39777810652fcc5f724c274e8bd7ce705f93d4
x86_64_v2 libcurl-devel-8.12.1-4.el10_2.6.x86_64_v2.rpm fde46a8d542aca0fc9793624cf8279c49f00bee64671ef8fb0badaf93a92ceb4
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.