Bug 2497470
| Summary: | CVE-2026-8932 davix: libcurl: Security feature bypass due to improper mTLS connection reuse [epel-all] | ||
|---|---|---|---|
| Product: | [Fedora] Fedora EPEL | Reporter: | Jon Moroney <jmoroney> |
| Component: | davix | Assignee: | Mihai Patrascoiu <mihai.patrascoiu> |
| Status: | ASSIGNED --- | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | epel10 | CC: | adev88, mattias.ellert, mihai.patrascoiu |
| Target Milestone: | --- | Keywords: | Reopened, Security, SecurityTracking |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | {"flaws": ["e158f066-055b-4c38-9c35-fbfc2a260b16"]} | ||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2026-09-07 05:54:13 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 2496759 | ||
|
Description
Jon Moroney
2026-07-06 20:11:31 UTC
Hello, This CVE affects Davix on EPEL8 platform, as over there we bundle libcurl v7.69.0. Can patch our Davix codebase once upstream patch backport is published for curl v7.69.0. Cheers, Mihai |