Release date:
2026-07-31 15:01:40 UTC
Description:
- CVE-2025-53859: fix buffer over-read in the SMTP authentication path that
could disclose worker process memory to the authentication server
- CVE-2026-28753: validate host names resolved from the client address to
prevent header injection into auth_http and XCLIENT requests
- CVE-2026-40701: fix use-after-free by cancelling a pending OCSP responder
resolve when the client connection is closed
- CVE-2026-42934: fix buffer over-read in the charset filter when a UTF-8
sequence is split across several buffers
- CVE-2026-48142: fix remaining buffer over-read in the charset filter on
invalid UTF-8 sequences
- CVE-2026-42946: reset the parsing state and restore the buffer position
after an unrecognized upstream status line in the scgi and uwsgi modules
Updated packages:
-
nginx-1.20.1-22.el9_6.3.alma.2.tuxcare.els9.x86_64.rpm
sha:9b24261ade5ae32598af5151722a572fe532b203a760099ad3e339d5969f9ae1
-
nginx-all-modules-1.20.1-22.el9_6.3.alma.2.tuxcare.els9.noarch.rpm
sha:07f95a42053ad6ecc036d5743d016f25208097d96a6c0cbee7c178eb71052579
-
nginx-core-1.20.1-22.el9_6.3.alma.2.tuxcare.els9.x86_64.rpm
sha:49e9638c0ed12b7f5e9834372600e042a2d62f13a4c96fdc9b4f80a1705efa0b
-
nginx-filesystem-1.20.1-22.el9_6.3.alma.2.tuxcare.els9.noarch.rpm
sha:b4e6246fbc0ef6f63e94865bb87c455ba496208d7a6f7033cd3670e13c1ff234
-
nginx-mod-devel-1.20.1-22.el9_6.3.alma.2.tuxcare.els9.x86_64.rpm
sha:ba5eb90d8190c7ca0070fcdfdafd0d222ee2889c3de3444730ace1fc8354e3ba
-
nginx-mod-http-image-filter-1.20.1-22.el9_6.3.alma.2.tuxcare.els9.x86_64.rpm
sha:6577060a0cc6bc593b3a58bb173cc58b74417abebb780f105ab8d6c786c1acaf
-
nginx-mod-http-perl-1.20.1-22.el9_6.3.alma.2.tuxcare.els9.x86_64.rpm
sha:adcccf0d88c0ff739327d659c1d8cbc1ed0f8f95dbdb10c39a62b5716ce9e1de
-
nginx-mod-http-xslt-filter-1.20.1-22.el9_6.3.alma.2.tuxcare.els9.x86_64.rpm
sha:b8c6683871e51971a8bdc0a43b831464cda9beeacf836acd39b4cd61c0c37b6d
-
nginx-mod-mail-1.20.1-22.el9_6.3.alma.2.tuxcare.els9.x86_64.rpm
sha:3ad507bb81951f0a3cb571a3253bd4214856a045e2dfeb32e8e15eb78261172c
-
nginx-mod-stream-1.20.1-22.el9_6.3.alma.2.tuxcare.els9.x86_64.rpm
sha:254fdaa3f1f03635b5726893f0a06467e631e37e29969d3c6be2b91b2b1cd51e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.