Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:1350 - Security Advisory
Issued:
2026-01-27
Updated:
2026-01-27

RHSA-2026:1350 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: curl security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for curl is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.

Security Fix(es):

  • curl: libcurl: Curl out of bounds read for cookie path (CVE-2025-9086)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64

Fixes

  • BZ - 2394750 - CVE-2025-9086 curl: libcurl: Curl out of bounds read for cookie path
  • RHEL-129493 - curl segfaults when sending data file larger than speed limit [rhel-9.7.z]

CVEs

  • CVE-2025-9086

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
curl-7.76.1-35.el9_7.3.src.rpm SHA-256: 670afd4496d5eec73b99528af258cf87be65cf4567c9e7c76a3c7508af3e6687
x86_64
curl-7.76.1-35.el9_7.3.x86_64.rpm SHA-256: 5b01bc58d38b77f3ff9a8c88a512b9a35c5a7fbecb6e3f734212008ea3bdc30b
curl-debuginfo-7.76.1-35.el9_7.3.i686.rpm SHA-256: 50b7bc9b96ca7f03eec944e4176e3fd280ea9d9d847d9686078cb8195b9004f8
curl-debuginfo-7.76.1-35.el9_7.3.i686.rpm SHA-256: 50b7bc9b96ca7f03eec944e4176e3fd280ea9d9d847d9686078cb8195b9004f8
curl-debuginfo-7.76.1-35.el9_7.3.x86_64.rpm SHA-256: 04ebc1849bddc9121fcaea142d279a0c2e4a276094c9ba60d74655317310d982
curl-debuginfo-7.76.1-35.el9_7.3.x86_64.rpm SHA-256: 04ebc1849bddc9121fcaea142d279a0c2e4a276094c9ba60d74655317310d982
curl-debugsource-7.76.1-35.el9_7.3.i686.rpm SHA-256: 12601508d7810b53f841782520c42dbc1dcdf4683b87a12c4c7b0203e4bb65fa
curl-debugsource-7.76.1-35.el9_7.3.i686.rpm SHA-256: 12601508d7810b53f841782520c42dbc1dcdf4683b87a12c4c7b0203e4bb65fa
curl-debugsource-7.76.1-35.el9_7.3.x86_64.rpm SHA-256: a523cd5c8cedf6562f7d2c71b3eb33a0eb5b52ede9e47aece2f2ed9eca9d8369
curl-debugsource-7.76.1-35.el9_7.3.x86_64.rpm SHA-256: a523cd5c8cedf6562f7d2c71b3eb33a0eb5b52ede9e47aece2f2ed9eca9d8369
curl-minimal-7.76.1-35.el9_7.3.x86_64.rpm SHA-256: 96498d92a94cff118163ca6e344ad3b578d8f7f38dfe1b96f05edc2a25b45fd4
curl-minimal-debuginfo-7.76.1-35.el9_7.3.i686.rpm SHA-256: 8c5a24604b36f2f856cc09ef85df245c64b00dd6c089e48b26e3f9416570f424
curl-minimal-debuginfo-7.76.1-35.el9_7.3.i686.rpm SHA-256: 8c5a24604b36f2f856cc09ef85df245c64b00dd6c089e48b26e3f9416570f424
curl-minimal-debuginfo-7.76.1-35.el9_7.3.x86_64.rpm SHA-256: 7fff15baed2f83eabe27952c74102353bbcba8dfe96b3d057069104922cbe0a1
curl-minimal-debuginfo-7.76.1-35.el9_7.3.x86_64.rpm SHA-256: 7fff15baed2f83eabe27952c74102353bbcba8dfe96b3d057069104922cbe0a1
libcurl-7.76.1-35.el9_7.3.i686.rpm SHA-256: 787dc8d791d956bb21de3c1b87ddbdeb9e98619105a53275dd2c5987d96e003a
libcurl-7.76.1-35.el9_7.3.x86_64.rpm SHA-256: 76a6cc994c5b63968854eed67230e73c8fd70b9f59c9f274c3042a85fcbe490f
libcurl-debuginfo-7.76.1-35.el9_7.3.i686.rpm SHA-256: fe1f4105a23a75f72be900a420320d279bce9c3cb92d76f901260219df03c5f4
libcurl-debuginfo-7.76.1-35.el9_7.3.i686.rpm SHA-256: fe1f4105a23a75f72be900a420320d279bce9c3cb92d76f901260219df03c5f4
libcurl-debuginfo-7.76.1-35.el9_7.3.x86_64.rpm SHA-256: 7ee4234d52ceea4eec9f0d4d32b03e51536adf3855d5157e7aba58e6799d1c70
libcurl-debuginfo-7.76.1-35.el9_7.3.x86_64.rpm SHA-256: 7ee4234d52ceea4eec9f0d4d32b03e51536adf3855d5157e7aba58e6799d1c70
libcurl-devel-7.76.1-35.el9_7.3.i686.rpm SHA-256: 6b9caf45987d5a44e47716abf56720a956d678c970474015a4eba27456e5eb51
libcurl-devel-7.76.1-35.el9_7.3.x86_64.rpm SHA-256: ab5decea4ee43121ae221b13c781d10688ee99af688b7f48c8aa9afd99df01d0
libcurl-minimal-7.76.1-35.el9_7.3.i686.rpm SHA-256: 49e5a5e078b1b87c07e65dc0d0a6d329326695da35d2d9266e4eab9dd1ab5d89
libcurl-minimal-7.76.1-35.el9_7.3.x86_64.rpm SHA-256: b192815df8073689a55cdcc06deff482d5eefea260270363c8824fd3c4a06bf4
libcurl-minimal-debuginfo-7.76.1-35.el9_7.3.i686.rpm SHA-256: 027647edb03b53a51624d38a3f81198ce8ce48844b1e83bae98979ba00412369
libcurl-minimal-debuginfo-7.76.1-35.el9_7.3.i686.rpm SHA-256: 027647edb03b53a51624d38a3f81198ce8ce48844b1e83bae98979ba00412369
libcurl-minimal-debuginfo-7.76.1-35.el9_7.3.x86_64.rpm SHA-256: 54f10d9d47d27b73b8b62a02857e539b8abaebcd10ce2c4842ba57e5fd2ec343
libcurl-minimal-debuginfo-7.76.1-35.el9_7.3.x86_64.rpm SHA-256: 54f10d9d47d27b73b8b62a02857e539b8abaebcd10ce2c4842ba57e5fd2ec343

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
curl-7.76.1-35.el9_7.3.src.rpm SHA-256: 670afd4496d5eec73b99528af258cf87be65cf4567c9e7c76a3c7508af3e6687
s390x
curl-7.76.1-35.el9_7.3.s390x.rpm SHA-256: 28d114798ac0f43619f12602109f10d187e91935affa4c7a30ebd92c0c3e1920
curl-debuginfo-7.76.1-35.el9_7.3.s390x.rpm SHA-256: 6b11e4eef824f0ac4945a252a79bf4d065df81184efd0d79723802a8d2a45815
curl-debuginfo-7.76.1-35.el9_7.3.s390x.rpm SHA-256: 6b11e4eef824f0ac4945a252a79bf4d065df81184efd0d79723802a8d2a45815
curl-debugsource-7.76.1-35.el9_7.3.s390x.rpm SHA-256: d200d34fece684195b73f40f93819e00b07c416a5d587e7bc014b0e1e770c440
curl-debugsource-7.76.1-35.el9_7.3.s390x.rpm SHA-256: d200d34fece684195b73f40f93819e00b07c416a5d587e7bc014b0e1e770c440
curl-minimal-7.76.1-35.el9_7.3.s390x.rpm SHA-256: fe8db3e776b8a02131800057fe802e251a4517f1b7a01e3024ef97ae0b8e9dd3
curl-minimal-debuginfo-7.76.1-35.el9_7.3.s390x.rpm SHA-256: 1ad06cf77a6c6104e1a9627614fe12824fedef81b32c6610ff790ae4b49b95b5
curl-minimal-debuginfo-7.76.1-35.el9_7.3.s390x.rpm SHA-256: 1ad06cf77a6c6104e1a9627614fe12824fedef81b32c6610ff790ae4b49b95b5
libcurl-7.76.1-35.el9_7.3.s390x.rpm SHA-256: 8c27ace08b127c9ade5acfc6e6039482f96d6df1ea387e29170114129cc37798
libcurl-debuginfo-7.76.1-35.el9_7.3.s390x.rpm SHA-256: 3c47cc62104f8412a145f1b33931ce5e7e275594d0e7c8bb9d7a5718fc80d355
libcurl-debuginfo-7.76.1-35.el9_7.3.s390x.rpm SHA-256: 3c47cc62104f8412a145f1b33931ce5e7e275594d0e7c8bb9d7a5718fc80d355
libcurl-devel-7.76.1-35.el9_7.3.s390x.rpm SHA-256: de99925d2a1f45b50c62943eda65060376c4b0318fa45a943d692e8098739bcb
libcurl-minimal-7.76.1-35.el9_7.3.s390x.rpm SHA-256: d1ebd6099409746d96e6b817d4d0a1839ec4dd15dd66380d069427d652d1f831
libcurl-minimal-debuginfo-7.76.1-35.el9_7.3.s390x.rpm SHA-256: 8e01befeb0cd0f6410df5dbbc1b46d743d121450758cd5f66b508d786db2bf42
libcurl-minimal-debuginfo-7.76.1-35.el9_7.3.s390x.rpm SHA-256: 8e01befeb0cd0f6410df5dbbc1b46d743d121450758cd5f66b508d786db2bf42

Red Hat Enterprise Linux for Power, little endian 9

SRPM
curl-7.76.1-35.el9_7.3.src.rpm SHA-256: 670afd4496d5eec73b99528af258cf87be65cf4567c9e7c76a3c7508af3e6687
ppc64le
curl-7.76.1-35.el9_7.3.ppc64le.rpm SHA-256: 089b35068610a9c120fcb60e0043efb776f16e1146a433cd9acc01cc8c910420
curl-debuginfo-7.76.1-35.el9_7.3.ppc64le.rpm SHA-256: f3609eb509c20fb40190711ca1689728520e424a964d7caab18dfba8843d7407
curl-debuginfo-7.76.1-35.el9_7.3.ppc64le.rpm SHA-256: f3609eb509c20fb40190711ca1689728520e424a964d7caab18dfba8843d7407
curl-debugsource-7.76.1-35.el9_7.3.ppc64le.rpm SHA-256: 5a34defbad917fa67d3b768051d8563e0ccd79e0cdc0e0a013b71772ecc0a790
curl-debugsource-7.76.1-35.el9_7.3.ppc64le.rpm SHA-256: 5a34defbad917fa67d3b768051d8563e0ccd79e0cdc0e0a013b71772ecc0a790
curl-minimal-7.76.1-35.el9_7.3.ppc64le.rpm SHA-256: cd5ac960edc3bc82b079fde27ecd3190b4cc77dd60bfce143eba5eb097f1b134
curl-minimal-debuginfo-7.76.1-35.el9_7.3.ppc64le.rpm SHA-256: 0827e550db9e01b4cc7107e93d66e481aae1208f5e26c16f714be4890adbe4cb
curl-minimal-debuginfo-7.76.1-35.el9_7.3.ppc64le.rpm SHA-256: 0827e550db9e01b4cc7107e93d66e481aae1208f5e26c16f714be4890adbe4cb
libcurl-7.76.1-35.el9_7.3.ppc64le.rpm SHA-256: 4fe25624bf8d64e84154fbb95d64567dc6d50d841ebf41d78fdc3445b84f25b6
libcurl-debuginfo-7.76.1-35.el9_7.3.ppc64le.rpm SHA-256: 301e0ffc4a2c52e53a26e9b557a52f0ad703ce7a785a67f2feef9157b732fd5b
libcurl-debuginfo-7.76.1-35.el9_7.3.ppc64le.rpm SHA-256: 301e0ffc4a2c52e53a26e9b557a52f0ad703ce7a785a67f2feef9157b732fd5b
libcurl-devel-7.76.1-35.el9_7.3.ppc64le.rpm SHA-256: ebc87feb615fd9a26da7455b5b787bb21f07156c9b8b5b57b970231e251c825d
libcurl-minimal-7.76.1-35.el9_7.3.ppc64le.rpm SHA-256: 2cf7dbc31082911a629ea1379ebffb56d2bb58f60efda89d299257f17b3b916c
libcurl-minimal-debuginfo-7.76.1-35.el9_7.3.ppc64le.rpm SHA-256: a52e69ee5379429fbd9d70055d2376341ff4e1a2ed9093d8aea32c2c35f904a2
libcurl-minimal-debuginfo-7.76.1-35.el9_7.3.ppc64le.rpm SHA-256: a52e69ee5379429fbd9d70055d2376341ff4e1a2ed9093d8aea32c2c35f904a2

Red Hat Enterprise Linux for ARM 64 9

SRPM
curl-7.76.1-35.el9_7.3.src.rpm SHA-256: 670afd4496d5eec73b99528af258cf87be65cf4567c9e7c76a3c7508af3e6687
aarch64
curl-7.76.1-35.el9_7.3.aarch64.rpm SHA-256: 2ed44feaa9dd15834295493690fd383d21d226ab1801be9daf4234d064ccc428
curl-debuginfo-7.76.1-35.el9_7.3.aarch64.rpm SHA-256: 7d1e44b8b84b4020c650edfd4e6442f556a0ad85f9a0edb7205779a28016f48d
curl-debuginfo-7.76.1-35.el9_7.3.aarch64.rpm SHA-256: 7d1e44b8b84b4020c650edfd4e6442f556a0ad85f9a0edb7205779a28016f48d
curl-debugsource-7.76.1-35.el9_7.3.aarch64.rpm SHA-256: dd6e6df588998b6b5b006a01917f1ee1e18f6eef834cd15cb487622b9f1054f9
curl-debugsource-7.76.1-35.el9_7.3.aarch64.rpm SHA-256: dd6e6df588998b6b5b006a01917f1ee1e18f6eef834cd15cb487622b9f1054f9
curl-minimal-7.76.1-35.el9_7.3.aarch64.rpm SHA-256: 8f383abef8a782bad3fb78305fb977f94aa9c405b33b2255bfe40470fb9f69b9
curl-minimal-debuginfo-7.76.1-35.el9_7.3.aarch64.rpm SHA-256: 0398af046de2c1fdecfa7a8083fc39db360226cb343de899638ace9ea6763d0a
curl-minimal-debuginfo-7.76.1-35.el9_7.3.aarch64.rpm SHA-256: 0398af046de2c1fdecfa7a8083fc39db360226cb343de899638ace9ea6763d0a
libcurl-7.76.1-35.el9_7.3.aarch64.rpm SHA-256: ab4a5868ad994f4776b32e92833ac5112cdc81c99fb78e76d8607e9c88ae2bf9
libcurl-debuginfo-7.76.1-35.el9_7.3.aarch64.rpm SHA-256: c46956f4419e8a18e1ea5ef3bf0ac5ac82443b8bf19f77eeb309612e19b68c34
libcurl-debuginfo-7.76.1-35.el9_7.3.aarch64.rpm SHA-256: c46956f4419e8a18e1ea5ef3bf0ac5ac82443b8bf19f77eeb309612e19b68c34
libcurl-devel-7.76.1-35.el9_7.3.aarch64.rpm SHA-256: 9d6be0610d29bd3485954fbe50e44b5919b61348e12fd011d15362ae97dc06b0
libcurl-minimal-7.76.1-35.el9_7.3.aarch64.rpm SHA-256: 1c1842809017627ff3bf6b7095167e47db01f0675c6a1c7f34c39ea40d32c253
libcurl-minimal-debuginfo-7.76.1-35.el9_7.3.aarch64.rpm SHA-256: 5abad90fa9660c09b949f6878f15735b55278d3a326425360793a9670a5d5afc
libcurl-minimal-debuginfo-7.76.1-35.el9_7.3.aarch64.rpm SHA-256: 5abad90fa9660c09b949f6878f15735b55278d3a326425360793a9670a5d5afc

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility