[CLSA-2026:1785327397] nginx: Fix of CVE-2026-48142
Type:
security
Severity:
Moderate
Release date:
2026-07-29 12:16:47 UTC
Description:
- CVE-2026-48142: heap out-of-bounds read in ngx_http_charset_recode_from_utf8() when an invalid UTF-8 sequence split across buffers rewinds src before the buffer start, on locations recoding source_charset utf-8 to another charset
CVEs fixed:
Updated packages:
  • nginx-1.14.1-9.module_el8.4.0+2453+95736f1a.tuxcare.els13.x86_64.rpm
    sha:7f5cfc4b0dfbd09045591402889be43a9dc76291d3c96cd737e01d0c171163a8
  • nginx-all-modules-1.14.1-9.module_el8.4.0+2453+95736f1a.tuxcare.els13.noarch.rpm
    sha:5e9be408fc919191b0bca4d4d05a9aa1dd49c2012dc5dcf5b2eeb7cefcce3aea
  • nginx-filesystem-1.14.1-9.module_el8.4.0+2453+95736f1a.tuxcare.els13.noarch.rpm
    sha:a362942a926047f949067aa93f38d75e552d2bc3abbe8c1c25df16fa4071d961
  • nginx-mod-http-image-filter-1.14.1-9.module_el8.4.0+2453+95736f1a.tuxcare.els13.x86_64.rpm
    sha:3cb30caba07f22611d7ff677363f5d88085995e0a2d15841d22b79558918a91e
  • nginx-mod-http-perl-1.14.1-9.module_el8.4.0+2453+95736f1a.tuxcare.els13.x86_64.rpm
    sha:cc81126b7f75beb31aa7580576d1d6751aebb758773653d4f13301c871182b21
  • nginx-mod-http-xslt-filter-1.14.1-9.module_el8.4.0+2453+95736f1a.tuxcare.els13.x86_64.rpm
    sha:1eefe0793279dc1fa8851ee5a0275bc65ab7725d823d551da68cde9312d137b2
  • nginx-mod-mail-1.14.1-9.module_el8.4.0+2453+95736f1a.tuxcare.els13.x86_64.rpm
    sha:b49939d67fa686e6cdac1233c3ba183faa0c64d210d55f3c93ac6c7fdc40d981
  • nginx-mod-stream-1.14.1-9.module_el8.4.0+2453+95736f1a.tuxcare.els13.x86_64.rpm
    sha:bd6bbb46036b0a0df04bc443df7bcb60e00d6e057202ff9345d82dcad51dbf9c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.