{"id":"CLSA-2026-1773316266","summary":"Fix CVE(s): CVE-2025-14524, CVE-2025-15079, CVE-2025-15224","details":"   * SECURITY UPDATE: OAuth2 bearer token leak on cross-protocol redirect\n     - debian/patches/CVE-2025-14524.patch: do not use bearer when following\n       redirect unless allow_auth_to_other_hosts is set\n     - CVE-2025-14524\n   * SECURITY UPDATE: libssh global known_hosts override\n     - debian/patches/CVE-2025-15079-CVE-2025-15224.patch: set\n       SSH_OPTIONS_GLOBAL_KNOWNHOSTS to same path as SSH_OPTIONS_KNOWNHOSTS\n     - CVE-2025-15079\n   * SECURITY UPDATE: libssh key passphrase bypass without agent set\n     - debian/patches/CVE-2025-15079-CVE-2025-15224.patch: require private\n       key or CURLSSH_AUTH_AGENT for public key auth\n     - CVE-2025-15224","modified":"2026-06-04T09:45:55.845762548Z","published":"2026-03-12T11:51:10Z","upstream":["CVE-2025-14524","CVE-2025-15079","CVE-2025-15224"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/ubuntu20.04els/CLSA-2026-1773316266.html"}],"affected":[{"package":{"name":"curl","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/curl?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.68.0-1ubuntu2.25+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1773316266.json"}},{"package":{"name":"libcurl3-gnutls","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/libcurl3-gnutls?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.68.0-1ubuntu2.25+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1773316266.json"}},{"package":{"name":"libcurl3-nss","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/libcurl3-nss?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.68.0-1ubuntu2.25+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1773316266.json"}},{"package":{"name":"libcurl4","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/libcurl4?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.68.0-1ubuntu2.25+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1773316266.json"}},{"package":{"name":"libcurl4-doc","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/libcurl4-doc?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.68.0-1ubuntu2.25+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1773316266.json"}},{"package":{"name":"libcurl4-gnutls-dev","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/libcurl4-gnutls-dev?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.68.0-1ubuntu2.25+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1773316266.json"}},{"package":{"name":"libcurl4-nss-dev","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/libcurl4-nss-dev?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.68.0-1ubuntu2.25+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1773316266.json"}},{"package":{"name":"libcurl4-openssl-dev","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/libcurl4-openssl-dev?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.68.0-1ubuntu2.25+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1773316266.json"}}],"schema_version":"1.7.5"}