shield
Security update for curl
SUSE-SLE-Micro-5.4-2026-3958
This update for curl fixes the following issues: - CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). - CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). - CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). Changes for curl: - Call http_size() first to prioritize Transfer-Encoding: chunked over a zero Content-Length empty body check (bsc#1264971)
-
Release DateSep 3 2026
-
ReferencesBugzilla: 1262633, 1263440, 1264971, 1268412, 1277476, 1277479, 1277480
CVEs: CVE-2026-5773, CVE-2026-7168, CVE-2026-8926, CVE-2026-13608, CVE-2026-80229, CVE-2026-80230 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
SUSE Linux Enterprise Micro 5.4 aarch64
-
Packages
SUSE Linux Enterprise Micro 5.4 s390x
-
Packages
SUSE Linux Enterprise Micro 5.4 x86_64
-
Packages