curl-8.18.0-9.fc44
FEDORA-2026-2f88b83676
Packages in this update:
- curl-8.18.0-9.fc44
- Fix QUIC zero-length UDP datagrams busy-loop (CVE-2026-11352)
- Fix WS Auto-PONG memory exhaustion (CVE-2026-11586)
- Fix proto-default skips SSH verification (CVE-2026-12064)
- Fix wrong STARTTLS connection reuse (CVE-2026-8286)
- Fix SASL double-free (CVE-2026-8925)
- Fix env-set cross-proxy Digest auth state leak (CVE-2026-8927)
- Fix sending old referer (CVE-2026-9546)
- Fix exposing HTTP/3 early data (CVE-2026-9545)
- Fix UAF after pause in socket callback (CVE-2026-9080)