stable

curl-8.18.0-6.fc44

FEDORA-2026-f13d888b0f created by jamacku 3 months ago for Fedora 44
  • Fix bad reuse of HTTP Negotiate connection (CVE-2026-1965)
  • Fix token leak with redirect and netrc (CVE-2026-3783)
  • Fix wrong proxy connection reuse with credentials (CVE-2026-3784)
  • Fix use after free in SMB connection reuse (CVE-2026-3805)

  • Fix Could not find digest algorithm UNDEF (NID 0)

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2026-f13d888b0f

This update has been submitted for testing by jamacku.

3 months ago

This update's test gating status has been changed to 'waiting'.

3 months ago

This update's test gating status has been changed to 'passed'.

3 months ago
User Icon nixuser commented & provided feedback 3 months ago
karma

Working for me.

This update has been pushed to testing.

3 months ago
User Icon bojan commented & provided feedback 3 months ago
karma

Works.

This update can be pushed to stable now if the maintainer wishes

3 months ago
User Icon filiperosset commented & provided feedback 3 months ago
karma

no regressions noted

This update has been submitted for stable by bodhi.

There is an ongoing freeze; this will be pushed to stable after the freeze is over.

3 months ago

This update has obsoleted curl-8.18.0-5.fc44, and has inherited its bugs and notes.

3 months ago
karma
karma
User Icon jamacku commented & provided feedback 3 months ago

Thank you for testing this update!

User Icon derekenz commented & provided feedback 3 months ago
karma

Works

no issues

User Icon ankursinha commented & provided feedback 3 months ago
karma

No issues noted

User Icon ankursinha commented & provided feedback 3 months ago
karma

No issues noted

This update has been pushed to stable.

3 months ago

Please log in to add feedback.

Metadata
Type
security
Severity
medium
Karma
7
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
14 days
Dates
submitted
3 months ago
in testing
3 months ago
in stable
3 months ago
approved
3 months ago
BZ#2438170 OBJ_find_sigid_algs() returns NID_undef for ML-DSA certificate
0
0
BZ#2457259 CVE-2026-3805 curl: curl: Arbitrary code execution or Denial of Service via use-after-free in SMB request handling [fedora-44]
0
0
BZ#2457261 CVE-2026-1965 curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication [fedora-44]
0
0
BZ#2457262 CVE-2026-3784 curl: curl: Unauthorized access due to improper HTTP proxy connection reuse [fedora-44]
0
0
BZ#2457263 CVE-2026-3783 curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect [fedora-44]
0
0

Automated Test Results

Test Cases

0 0 Test Case curl