СloudLinux Blog

CloudLinux OS 6 ELS: curl package with the fix for the CVE-2021-22898 gradual rollout

Written by Inessa Atmachian | Jun 29, 2021 5:32:26 PM

A new updated curl package with the fix for the CVE-2021-22898 within CloudLinux OS 6 ELS has been scheduled for gradual rollout from our production repository.

Rollout slot: 4
Rolled out to: 1%
ETA for 100% rollout: July 7

CHANGELOG

curl-7.19.7-57.el6.cloudlinux.els

  • Added check sscanf() for correct number of matches (CVE-2021-22898)

UPDATE COMMAND

yum update curl*

IMMEDIATE UPDATE (VIA BYPASS)

yum update curl* --enablerepo=cloudlinux-rollout-4-bypass