AlmaLinux 9.2 [TuxCare] Security Update: curl / curl-minimal / libcurl / libcurl-devel / libcurl-minimal Multiple Vulnerabilities (ALMALINUX9.2:CLSA-2026:1785847606)

critical Nessus Plugin ID 352907

Synopsis

The AlmaLinux host is missing one or more security updates.

Description

The AlmaLinux 9.2 host has packages installed that are affected by multiple vulnerabilities as referenced in the TuxCare ALMALINUX9.2:CLSA-2026:1785847606 advisory.

- A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted. (CVE-2026-4873)

- curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy needs credentials 3. the second proxy uses no credentials 4. while using the first proxy (using say `http://`), curl is asked to follow a redirect to a URL using another scheme (say `https://`), accessed using a second, different, proxy (CVE-2026-6253)

- When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances. (CVE-2026-6429)

- A flaw in curl's cookie parsing logic allows a malicious HTTP server to set super cookies that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains. (CVE-2026-8924)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in TuxCare advisory ALMALINUX9.2:CLSA-2026:1785847606.

See Also

https://cve.tuxcare.com/els/releases/CLSA-2026:1785847606

http://www.nessus.org/u?7fe8b607

Plugin Details

Severity: Critical

ID: 352907

File Name: tuxcare_alma_linux_9.2_CLSA-2026-1785847606.nasl

Version: 1.1

Type: Local

Published: 9/30/2026

Updated: 9/30/2026

Supported Sensors: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.81

Vendor

Vendor Severity: Moderate

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-8924

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/OS/extended-third-party, Host/local_checks_enabled, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/4/2026

Vulnerability Publication Date: 4/30/2026

Reference Information

CVE: CVE-2026-4873, CVE-2026-6253, CVE-2026-6429, CVE-2026-8924

CLSA: 2026:1785847606