Release date:
2026-07-30 14:48:07 UTC
Description:
- CVE-2026-42946: fix buffer over-read and excessive memory allocation in
ngx_http_scgi_module and ngx_http_uwsgi_module when an upstream server
returns an unrecognized status line; reset r->state before falling back to
header parsing so the header parser no longer resumes from a status-line
state and reads through an uninitialized r->header_name_start, and reuse
r->header_name_start to backtrack the buffer position for status lines
split across reads
Updated packages:
-
nginx-1.20.1-14.el9_2.1.alma.1.tuxcare.els12.x86_64.rpm
sha:e16dd3ae0f13af1a8c90c97060fe434e7e9ea3464e521f7c755a21385a8f7ae2
-
nginx-all-modules-1.20.1-14.el9_2.1.alma.1.tuxcare.els12.noarch.rpm
sha:0709a01ddd03cbc9eb29d8f2b9ea123f8d9e71690149ed7ae155021d334b72c7
-
nginx-core-1.20.1-14.el9_2.1.alma.1.tuxcare.els12.x86_64.rpm
sha:50c9ae3e63c6602ef643cfac1c17cb819c2d3c024ae882e2959221962d0289e9
-
nginx-filesystem-1.20.1-14.el9_2.1.alma.1.tuxcare.els12.noarch.rpm
sha:30ae36c51d2d176570a76a935eda1529522e09390d8de90ce3d397051f6b98f8
-
nginx-mod-devel-1.20.1-14.el9_2.1.alma.1.tuxcare.els12.x86_64.rpm
sha:0435ea8d3227346568dfb39a8a59cc3475f339782057e6ea6867d27476cc2b3e
-
nginx-mod-http-image-filter-1.20.1-14.el9_2.1.alma.1.tuxcare.els12.x86_64.rpm
sha:58d8aeba6f69ab2f7f2c0a78bdf0cf013a2e32e7ecffcb6b6c8beefdbdeedda4
-
nginx-mod-http-perl-1.20.1-14.el9_2.1.alma.1.tuxcare.els12.x86_64.rpm
sha:156265aee03c27e825c1d4225a4d99068e1d2c199f38e04c2491dade1b120387
-
nginx-mod-http-xslt-filter-1.20.1-14.el9_2.1.alma.1.tuxcare.els12.x86_64.rpm
sha:635aa9afc9037f64e08997b16d9f8322d0ab90006b6b937bbfa910ec6f54dc2b
-
nginx-mod-mail-1.20.1-14.el9_2.1.alma.1.tuxcare.els12.x86_64.rpm
sha:c7ce66cb1af334b9026e53ebc9348e10772b361311555f7e321e5bd22797de7c
-
nginx-mod-stream-1.20.1-14.el9_2.1.alma.1.tuxcare.els12.x86_64.rpm
sha:e040567b0ca3ed74ef435709e9be81d87608e1f858f29f799d98d5d090cf8763
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.