ALAS2-2026-3953


Amazon Linux 2 (EOS) Security Advisory: ALAS2-2026-3953
Advisory Released Date: 2026-09-28
Advisory Updated Date: 2026-09-28
Severity: Important

Issue Overview:

When a user invokes curl using a schemeless URL combined with --proto-default sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error. (CVE-2026-12064)

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation. (CVE-2026-13608)

When CURLOPT_PINNEDPUBLICKEY is configured alongside options that disable standard peer verification (CURLOPT_SSL_VERIFYPEER = 0 and CURLOPT_SSL_VERIFYHOST = 0), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected. (CVE-2026-80230)

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not. (CVE-2026-8286)

A flaw in curl's cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains. (CVE-2026-8924)


Affected Packages:

curl


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update curl or yum update --advisory ALAS2-2026-3953 to update your system.

New Packages:
aarch64:
    curl-8.3.0-1.amzn2.0.13.aarch64
    libcurl-8.3.0-1.amzn2.0.13.aarch64
    libcurl-devel-8.3.0-1.amzn2.0.13.aarch64
    curl-debuginfo-8.3.0-1.amzn2.0.13.aarch64

i686:
    curl-8.3.0-1.amzn2.0.13.i686
    libcurl-8.3.0-1.amzn2.0.13.i686
    libcurl-devel-8.3.0-1.amzn2.0.13.i686
    curl-debuginfo-8.3.0-1.amzn2.0.13.i686

src:
    curl-8.3.0-1.amzn2.0.13.src

x86_64:
    curl-8.3.0-1.amzn2.0.13.x86_64
    libcurl-8.3.0-1.amzn2.0.13.x86_64
    libcurl-devel-8.3.0-1.amzn2.0.13.x86_64
    curl-debuginfo-8.3.0-1.amzn2.0.13.x86_64