This update for curl fixes the following issues:
* CVE-2026-1965: bad reuse of HTTP Negotiate connection (bsc#1259362).
* CVE-2026-3783: token leak with redirect and netrc (bsc#1259363).
* CVE-2026-3784: wrong proxy connection reuse with credentials (bsc#1259364).
* CVE-2026-3805: use after free in SMB connection reuse (bsc#1259365).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-885=1 openSUSE-SLE-15.6-2026-885=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-885=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-885=1
* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586)
* curl-debuginfo-8.14.1-150600.4.40.1
* curl-8.14.1-150600.4.40.1
* curl-mini-debugsource-8.14.1-150600.4.40.1
* libcurl-mini4-8.14.1-150600.4.40.1
* libcurl-mini4-debuginfo-8.14.1-150600.4.40.1
* curl-debugsource-8.14.1-150600.4.40.1
* libcurl4-debuginfo-8.14.1-150600.4.40.1
* libcurl4-8.14.1-150600.4.40.1
* libcurl-devel-8.14.1-150600.4.40.1
* openSUSE Leap 15.6 (noarch)
* curl-zsh-completion-8.14.1-150600.4.40.1
* curl-fish-completion-8.14.1-150600.4.40.1
* libcurl-devel-doc-8.14.1-150600.4.40.1
* openSUSE Leap 15.6 (x86_64)
* libcurl4-32bit-debuginfo-8.14.1-150600.4.40.1
* libcurl4-32bit-8.14.1-150600.4.40.1
* libcurl-devel-32bit-8.14.1-150600.4.40.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* libcurl4-64bit-8.14.1-150600.4.40.1
* libcurl-devel-64bit-8.14.1-150600.4.40.1
* libcurl4-64bit-debuginfo-8.14.1-150600.4.40.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* curl-debuginfo-8.14.1-150600.4.40.1
*...
Read the Full Advisory* bsc#1259362
* bsc#1259363
* bsc#1259364
* bsc#1259365
## References:
* https://www.suse.com/security/cve/CVE-2026-1965.html
* https://www.suse.com/security/cve/CVE-2026-3783.html
* https://www.suse.com/security/cve/CVE-2026-3784.html
* https://www.suse.com/security/cve/CVE-2026-3805.html
* https://bugzilla.suse.com/show_bug.cgi?id=1259362
* https://bugzilla.suse.com/show_bug.cgi?id=1259363
* https://bugzilla.suse.com/show_bug.cgi?id=1259364
* https://bugzilla.suse.com/show_bug.cgi?id=1259365
Get the latest Linux and open source security news straight to your inbox.