[CLSA-2026:1785509707] nginx: Fix of 6 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-31 15:01:40 UTC
Description:
- CVE-2025-53859: fix buffer over-read in the SMTP authentication path that could disclose worker process memory to the authentication server - CVE-2026-28753: validate host names resolved from the client address to prevent header injection into auth_http and XCLIENT requests - CVE-2026-40701: fix use-after-free by cancelling a pending OCSP responder resolve when the client connection is closed - CVE-2026-42934: fix buffer over-read in the charset filter when a UTF-8 sequence is split across several buffers - CVE-2026-48142: fix remaining buffer over-read in the charset filter on invalid UTF-8 sequences - CVE-2026-42946: reset the parsing state and restore the buffer position after an unrecognized upstream status line in the scgi and uwsgi modules
Updated packages:
  • nginx-1.20.1-22.el9_6.3.alma.2.tuxcare.els9.x86_64.rpm
    sha:9b24261ade5ae32598af5151722a572fe532b203a760099ad3e339d5969f9ae1
  • nginx-all-modules-1.20.1-22.el9_6.3.alma.2.tuxcare.els9.noarch.rpm
    sha:07f95a42053ad6ecc036d5743d016f25208097d96a6c0cbee7c178eb71052579
  • nginx-core-1.20.1-22.el9_6.3.alma.2.tuxcare.els9.x86_64.rpm
    sha:49e9638c0ed12b7f5e9834372600e042a2d62f13a4c96fdc9b4f80a1705efa0b
  • nginx-filesystem-1.20.1-22.el9_6.3.alma.2.tuxcare.els9.noarch.rpm
    sha:b4e6246fbc0ef6f63e94865bb87c455ba496208d7a6f7033cd3670e13c1ff234
  • nginx-mod-devel-1.20.1-22.el9_6.3.alma.2.tuxcare.els9.x86_64.rpm
    sha:ba5eb90d8190c7ca0070fcdfdafd0d222ee2889c3de3444730ace1fc8354e3ba
  • nginx-mod-http-image-filter-1.20.1-22.el9_6.3.alma.2.tuxcare.els9.x86_64.rpm
    sha:6577060a0cc6bc593b3a58bb173cc58b74417abebb780f105ab8d6c786c1acaf
  • nginx-mod-http-perl-1.20.1-22.el9_6.3.alma.2.tuxcare.els9.x86_64.rpm
    sha:adcccf0d88c0ff739327d659c1d8cbc1ed0f8f95dbdb10c39a62b5716ce9e1de
  • nginx-mod-http-xslt-filter-1.20.1-22.el9_6.3.alma.2.tuxcare.els9.x86_64.rpm
    sha:b8c6683871e51971a8bdc0a43b831464cda9beeacf836acd39b4cd61c0c37b6d
  • nginx-mod-mail-1.20.1-22.el9_6.3.alma.2.tuxcare.els9.x86_64.rpm
    sha:3ad507bb81951f0a3cb571a3253bd4214856a045e2dfeb32e8e15eb78261172c
  • nginx-mod-stream-1.20.1-22.el9_6.3.alma.2.tuxcare.els9.x86_64.rpm
    sha:254fdaa3f1f03635b5726893f0a06467e631e37e29969d3c6be2b91b2b1cd51e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.