[CLSA-2026:1790172301] nginx: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2026-09-24 09:14:30 UTC
Description:
- CVE-2026-27651: fix null pointer dereference in ngx_mail_auth_http_module when clearing the password in auth http requests with CRAM-MD5/APOP - CVE-2026-27654: fix heap buffer overflow in ngx_http_dav_module when a COPY/MOVE destination URI is shorter than the location alias - CVE-2026-27654: also require the COPY/MOVE Destination to match the aliased location prefix, and tighten ngx_http_map_uri_to_path() accordingly - CVE-2026-27784: fix integer overflow in ngx_http_mp4_module atom entry count validation on 32-bit platforms
Updated packages:
  • nginx-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
    sha:9114f1fc338bdca0409c7a2679477351cc190d30523d98a7ac7a243093c4eacd
  • nginx-all-modules-1.20.1-10.el7.tuxcare.els9.noarch.rpm
    sha:1c555447d1e2d44663079eb024f7c7aebdd96d7dd308e8895891ef5263b5cb0d
  • nginx-filesystem-1.20.1-10.el7.tuxcare.els9.noarch.rpm
    sha:df4bc699663a6c758598139f98288883c3ec371e356120b27f2866d3f9deb1ef
  • nginx-mod-devel-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
    sha:73aae9b3ec59246e14bc557723efbe4d8b6b101a43d365ab9846ab4f978fcbf3
  • nginx-mod-http-image-filter-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
    sha:c616bce6e9e6606741c767401dd11dae1da22ce61e7780f9a107d24d02d79838
  • nginx-mod-http-perl-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
    sha:7c164e46bdb98bd06ad8326eb21423aa5d46e015c7a6a6be214ba29ed0962ea0
  • nginx-mod-http-xslt-filter-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
    sha:fe40695429e572b1ed25bf42cdc341067adc177941c8d7d8be55abb0d8c6c80c
  • nginx-mod-mail-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
    sha:dba1632eeac44320af8a5f082d6d34e29becbf1a7afa6a52a87dd1fddae67073
  • nginx-mod-stream-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
    sha:c788fc86b2c9d7536e747ae3eba081b97ca437b7e7b82c13a3d040c0f05fa190
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.