[El-errata] ELSA-2026-69125 Important: Oracle Linux 10 curl security update
Errata Announcements for Oracle Linux
el-errata at oss.oracle.com
Wed Sep 23 17:56:15 UTC 2026
Oracle Linux Security Advisory ELSA-2026-69125
http://linux.oracle.com/errata/ELSA-2026-69125.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
curl-8.12.1-4.el10_2.6.x86_64.rpm
libcurl-8.12.1-4.el10_2.6.x86_64.rpm
libcurl-devel-8.12.1-4.el10_2.6.x86_64.rpm
libcurl-minimal-8.12.1-4.el10_2.6.x86_64.rpm
aarch64:
curl-8.12.1-4.el10_2.6.aarch64.rpm
libcurl-8.12.1-4.el10_2.6.aarch64.rpm
libcurl-devel-8.12.1-4.el10_2.6.aarch64.rpm
libcurl-minimal-8.12.1-4.el10_2.6.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/curl-8.12.1-4.el10_2.6.src.rpm
Related CVEs:
CVE-2026-8458
CVE-2026-8924
CVE-2026-8926
CVE-2026-8932
CVE-2026-9079
CVE-2026-11856
Description of changes:
[8.12.1-4.6]
- fix cookie injection via trailing dot super cookies (CVE-2026-8924)
- fix digest auth state leak on origin or credential change (CVE-2026-11856)
- fix netrc password lookup for non-matching login (CVE-2026-8926)
[8.12.1-4.5]
- fix proxy auth not cleared properly on NULL (CVE-2026-9079)
- fix incomplete mTLS config in connection reuse and session cache
(CVE-2026-8932)
- fix SASL service name connection reuse bypass (CVE-2026-8458)
More information about the El-errata
mailing list