[CLSA-2026:1785327873] nginx: Fix of CVE-2026-48142
Type:
security
Severity:
Moderate
Release date:
2026-07-29 12:24:44 UTC
Description:
- CVE-2026-48142: heap out-of-bounds read in ngx_http_charset_recode_from_utf8() when an invalid UTF-8 sequence split across buffers rewinds src before the buffer start, on locations recoding source_charset utf-8 to another charset
CVEs fixed:
Updated packages:
  • nginx-1.14.1-9.module_el8.5.0+2454+bd5b62b5.tuxcare.els13.x86_64.rpm
    sha:e401f39d92abaec160c1438121ae144f435415f2997b24bccf18969c01baf147
  • nginx-all-modules-1.14.1-9.module_el8.5.0+2454+bd5b62b5.tuxcare.els13.noarch.rpm
    sha:b0c210a9bf5b8babf76f7a364af0940f3f51d824cabe27d0283fc22c0f3efdc9
  • nginx-filesystem-1.14.1-9.module_el8.5.0+2454+bd5b62b5.tuxcare.els13.noarch.rpm
    sha:d132f048b012ae4ea9fe2f6a9412802de9dc8cbaea36b267e03fde276a69fd6b
  • nginx-mod-http-image-filter-1.14.1-9.module_el8.5.0+2454+bd5b62b5.tuxcare.els13.x86_64.rpm
    sha:06f1be8d4eaf2cfc9d5bc74667190fe3002dbb967fd727f907c44dfd90e08e3f
  • nginx-mod-http-perl-1.14.1-9.module_el8.5.0+2454+bd5b62b5.tuxcare.els13.x86_64.rpm
    sha:0dd9c6726c7b89d5c57c32acbfd9b1d883c3e40c49c684142c477fc1bc196ea2
  • nginx-mod-http-xslt-filter-1.14.1-9.module_el8.5.0+2454+bd5b62b5.tuxcare.els13.x86_64.rpm
    sha:1ec2aab5f97b1565f599ca9954cf4be1263124e2ec551c7bb06946ee7412fcb8
  • nginx-mod-mail-1.14.1-9.module_el8.5.0+2454+bd5b62b5.tuxcare.els13.x86_64.rpm
    sha:c7143f514fc58160ac6b85795b21711d494ea592dd491feb85dabd3d27377e89
  • nginx-mod-stream-1.14.1-9.module_el8.5.0+2454+bd5b62b5.tuxcare.els13.x86_64.rpm
    sha:257d11b9aa3b1b8ec71ee149e4e2d2b3efaa675ad58019114fc16c0c3fde308e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.