[El-errata] ELSA-2026-69125 Important: Oracle Linux 10 curl security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Wed Sep 23 17:56:15 UTC 2026


Oracle Linux Security Advisory ELSA-2026-69125

http://linux.oracle.com/errata/ELSA-2026-69125.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
curl-8.12.1-4.el10_2.6.x86_64.rpm
libcurl-8.12.1-4.el10_2.6.x86_64.rpm
libcurl-devel-8.12.1-4.el10_2.6.x86_64.rpm
libcurl-minimal-8.12.1-4.el10_2.6.x86_64.rpm

aarch64:
curl-8.12.1-4.el10_2.6.aarch64.rpm
libcurl-8.12.1-4.el10_2.6.aarch64.rpm
libcurl-devel-8.12.1-4.el10_2.6.aarch64.rpm
libcurl-minimal-8.12.1-4.el10_2.6.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/curl-8.12.1-4.el10_2.6.src.rpm

Related CVEs:

CVE-2026-8458
CVE-2026-8924
CVE-2026-8926
CVE-2026-8932
CVE-2026-9079
CVE-2026-11856




Description of changes:

[8.12.1-4.6]
- fix cookie injection via trailing dot super cookies (CVE-2026-8924)
- fix digest auth state leak on origin or credential change (CVE-2026-11856)
- fix netrc password lookup for non-matching login (CVE-2026-8926)

[8.12.1-4.5]
- fix proxy auth not cleared properly on NULL (CVE-2026-9079)
- fix incomplete mTLS config in connection reuse and session cache
  (CVE-2026-8932)
- fix SASL service name connection reuse bypass (CVE-2026-8458)




More information about the El-errata mailing list