Amazon Linux 2 (EOS) Security Advisory: ALAS2-2026-3953
Advisory Released Date: 2026-09-28
Advisory Updated Date: 2026-09-28
FAQs regarding Amazon Linux ALAS/CVE Severity
When a user invokes curl using a schemeless URL combined with --proto-default sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error. (CVE-2026-12064)
A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation. (CVE-2026-13608)
When CURLOPT_PINNEDPUBLICKEY is configured alongside options that disable standard peer verification (CURLOPT_SSL_VERIFYPEER = 0 and CURLOPT_SSL_VERIFYHOST = 0), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected. (CVE-2026-80230)
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not. (CVE-2026-8286)
A flaw in curl's cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains. (CVE-2026-8924)
Affected Packages:
curl
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update curl or yum update --advisory ALAS2-2026-3953 to update your system.
aarch64:
curl-8.3.0-1.amzn2.0.13.aarch64
libcurl-8.3.0-1.amzn2.0.13.aarch64
libcurl-devel-8.3.0-1.amzn2.0.13.aarch64
curl-debuginfo-8.3.0-1.amzn2.0.13.aarch64
i686:
curl-8.3.0-1.amzn2.0.13.i686
libcurl-8.3.0-1.amzn2.0.13.i686
libcurl-devel-8.3.0-1.amzn2.0.13.i686
curl-debuginfo-8.3.0-1.amzn2.0.13.i686
src:
curl-8.3.0-1.amzn2.0.13.src
x86_64:
curl-8.3.0-1.amzn2.0.13.x86_64
libcurl-8.3.0-1.amzn2.0.13.x86_64
libcurl-devel-8.3.0-1.amzn2.0.13.x86_64
curl-debuginfo-8.3.0-1.amzn2.0.13.x86_64