[CLSA-2026:1785422875] nginx: Fix of CVE-2026-42946
Type:
security
Severity:
Important
Release date:
2026-07-30 14:48:07 UTC
Description:
- CVE-2026-42946: fix buffer over-read and excessive memory allocation in ngx_http_scgi_module and ngx_http_uwsgi_module when an upstream server returns an unrecognized status line; reset r->state before falling back to header parsing so the header parser no longer resumes from a status-line state and reads through an uninitialized r->header_name_start, and reuse r->header_name_start to backtrack the buffer position for status lines split across reads
CVEs fixed:
Updated packages:
  • nginx-1.20.1-14.el9_2.1.alma.1.tuxcare.els12.x86_64.rpm
    sha:e16dd3ae0f13af1a8c90c97060fe434e7e9ea3464e521f7c755a21385a8f7ae2
  • nginx-all-modules-1.20.1-14.el9_2.1.alma.1.tuxcare.els12.noarch.rpm
    sha:0709a01ddd03cbc9eb29d8f2b9ea123f8d9e71690149ed7ae155021d334b72c7
  • nginx-core-1.20.1-14.el9_2.1.alma.1.tuxcare.els12.x86_64.rpm
    sha:50c9ae3e63c6602ef643cfac1c17cb819c2d3c024ae882e2959221962d0289e9
  • nginx-filesystem-1.20.1-14.el9_2.1.alma.1.tuxcare.els12.noarch.rpm
    sha:30ae36c51d2d176570a76a935eda1529522e09390d8de90ce3d397051f6b98f8
  • nginx-mod-devel-1.20.1-14.el9_2.1.alma.1.tuxcare.els12.x86_64.rpm
    sha:0435ea8d3227346568dfb39a8a59cc3475f339782057e6ea6867d27476cc2b3e
  • nginx-mod-http-image-filter-1.20.1-14.el9_2.1.alma.1.tuxcare.els12.x86_64.rpm
    sha:58d8aeba6f69ab2f7f2c0a78bdf0cf013a2e32e7ecffcb6b6c8beefdbdeedda4
  • nginx-mod-http-perl-1.20.1-14.el9_2.1.alma.1.tuxcare.els12.x86_64.rpm
    sha:156265aee03c27e825c1d4225a4d99068e1d2c199f38e04c2491dade1b120387
  • nginx-mod-http-xslt-filter-1.20.1-14.el9_2.1.alma.1.tuxcare.els12.x86_64.rpm
    sha:635aa9afc9037f64e08997b16d9f8322d0ab90006b6b937bbfa910ec6f54dc2b
  • nginx-mod-mail-1.20.1-14.el9_2.1.alma.1.tuxcare.els12.x86_64.rpm
    sha:c7ce66cb1af334b9026e53ebc9348e10772b361311555f7e321e5bd22797de7c
  • nginx-mod-stream-1.20.1-14.el9_2.1.alma.1.tuxcare.els12.x86_64.rpm
    sha:e040567b0ca3ed74ef435709e9be81d87608e1f858f29f799d98d5d090cf8763
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.