Fedora Account System
Red Hat Associate
Red Hat Customer
libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:69125 https://access.redhat.com/errata/RHSA-2026:69125
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:69126 https://access.redhat.com/errata/RHSA-2026:69126
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:72506 https://access.redhat.com/errata/RHSA-2026:72506