curl-7.76.1-40.el9_8.7
エラータID: AXSA:2026-1953:07
The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.
Security Fix(es):
* curl: libcurl: Unauthorized connection reuse due to a logical error (CVE-2026-8458)
* curl: Information disclosure due to uncleared proxy authentication state (CVE-2026-8927)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-8458
libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different "services". libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.
CVE-2026-8927
When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.
Update packages.
libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different "services". libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.
When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.
N/A
SRPMS
- curl-7.76.1-40.el9_8.7.src.rpm
MD5: 82d3613d54cb3eb98819b70c437a87c4
SHA-256: 890353f3070009fc9ebce0c5c536796589f3657118a71d9ce73537b0fc7cc0a5
Size: 2.46 MB
Asianux Server 9 for x86_64
- curl-7.76.1-40.el9_8.7.x86_64.rpm
MD5: eee962b75e6d7f2a22238c6ed47d01fa
SHA-256: 7427b3aeef6a9faed290e1e1f9028a1324f43191d30ebb0a2f0748da24f9837a
Size: 292.88 kB - curl-minimal-7.76.1-40.el9_8.7.x86_64.rpm
MD5: 3e9ec0d18112864de6815bda3f97bcf1
SHA-256: 4e2297b9ccca6d959098e809e4dcf06d04afac65b0f64c03560aed4246ef6357
Size: 126.58 kB - libcurl-7.76.1-40.el9_8.7.i686.rpm
MD5: 1e2e649e341d36c0135f1b861abd48de
SHA-256: e4b6a54c154404215420de3316aa913ac5f66437366e83ba224719359f458b30
Size: 310.23 kB - libcurl-7.76.1-40.el9_8.7.x86_64.rpm
MD5: ad18e7b715aec60a3a7b72e71690acf5
SHA-256: 04444aa2067d9aa9c2126fcb705dad4fb0c038a0794163a3727322a025979360
Size: 284.07 kB - libcurl-devel-7.76.1-40.el9_8.7.i686.rpm
MD5: 028c2e0f1bc633375e9bfc8c3cd2cd0a
SHA-256: 121f22ba4914f06353dc60126b0e5b35fa90f9ce754a65bb1e18ce4e462f22f0
Size: 0.96 MB - libcurl-devel-7.76.1-40.el9_8.7.x86_64.rpm
MD5: c15be4f8511eea664760c3bdc6a256ab
SHA-256: c424356a78400f423ee74bb392a0a53f98aabcffaf6f1a7a3b0c6b432ae31110
Size: 0.96 MB - libcurl-minimal-7.76.1-40.el9_8.7.i686.rpm
MD5: 68fcc9b21794f770a09e7b3907e037a5
SHA-256: f41ce8ae3cfc3d1b860c22730974a704c978db7290ad79863672cf8e5d60eba0
Size: 245.54 kB - libcurl-minimal-7.76.1-40.el9_8.7.x86_64.rpm
MD5: 3a72a94d639849a533af4b2bca80b776
SHA-256: cc7db9b17a5b1c86aff0b55ba431fcb4455350e6786bc2108954c02967c3863a
Size: 225.21 kB