[CLSA-2026:1790584773] nginx: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2026-09-28 08:39:45 UTC
Description:
- CVE-2026-27651: properly clear s->passwd in mail auth http requests to fix a null pointer dereference on CRAM-MD5/APOP retry - CVE-2026-27654: validate the Destination length for Dav COPY and MOVE to prevent an integer underflow and heap buffer overwrite when alias is used - CVE-2026-27654: also require the COPY/MOVE Destination to match the aliased location prefix, and tighten ngx_http_map_uri_to_path() accordingly - CVE-2026-27784: fix a possible integer overflow on 32-bit platforms while validating mp4 atom entry counts
Updated packages:
  • nginx-1.10.3-4.el6.tuxcare.els15.i686.rpm
    sha:538bf2eb53cdd17119c64d5a18634ba07f2fa19ed47f099f337bf2723b1e4737
  • nginx-1.10.3-4.el6.tuxcare.els15.x86_64.rpm
    sha:052c593fef3d5ee74f978a41ffad6c3feea5dd7218c79f045cf7d63810e2f913
  • nginx-all-modules-1.10.3-4.el6.tuxcare.els15.noarch.rpm
    sha:70865306e99f103d605a9639721313784dcea05a58a983c5ff3fe6b2cd43d200
  • nginx-filesystem-1.10.3-4.el6.tuxcare.els15.noarch.rpm
    sha:96700ee3a5dc96978b361f6e088335ee686e7f00ad9a8644e5a6228326cd5709
  • nginx-mod-http-geoip-1.10.3-4.el6.tuxcare.els15.i686.rpm
    sha:6fdf728b7eab03de573553adc46748281224086011b514a0bd0f5b9e05d34112
  • nginx-mod-http-geoip-1.10.3-4.el6.tuxcare.els15.x86_64.rpm
    sha:dc282ccca6b8f97194bb653e9f4070aed86f667f59892a9c9374d71c2d1d6776
  • nginx-mod-http-image-filter-1.10.3-4.el6.tuxcare.els15.i686.rpm
    sha:011f968f4d8872bba4808a0c037e16535a6fd61d25f7e6705f7d7f7bd6e524b5
  • nginx-mod-http-image-filter-1.10.3-4.el6.tuxcare.els15.x86_64.rpm
    sha:d574b07567d0ce4c1e645698727caaffdd5f60b5e532d7dde9f13b60bd10edab
  • nginx-mod-http-perl-1.10.3-4.el6.tuxcare.els15.i686.rpm
    sha:12430fa46de12ff3ad75ad89463f652b923cf7f437d173cf47454c787e397f9a
  • nginx-mod-http-perl-1.10.3-4.el6.tuxcare.els15.x86_64.rpm
    sha:193a08a7e4b768dc717b2332366923a87de4940b34c3b68e077744cfa7e01de9
  • nginx-mod-http-xslt-filter-1.10.3-4.el6.tuxcare.els15.i686.rpm
    sha:a61796e9ed13cb41fadb848c5fe5dc186d6be750ee5ccd7137a0aaa8f894c66a
  • nginx-mod-http-xslt-filter-1.10.3-4.el6.tuxcare.els15.x86_64.rpm
    sha:30718c7ecd149f10f7db92f1a9f612173d579bb3c2d087cde381162400dfda32
  • nginx-mod-mail-1.10.3-4.el6.tuxcare.els15.i686.rpm
    sha:0438429adb5775c3f179ce4f77e338e4fdb819ffe9b250f7e9b497488ac08034
  • nginx-mod-mail-1.10.3-4.el6.tuxcare.els15.x86_64.rpm
    sha:d3f1cd7f060becc7acbac778f5175a861e0c37a466363d0201d0cfda7410e908
  • nginx-mod-stream-1.10.3-4.el6.tuxcare.els15.i686.rpm
    sha:58da5f94a3a9556305c0d40f355507f77715bb6f9c041612a1a30d66600d67c5
  • nginx-mod-stream-1.10.3-4.el6.tuxcare.els15.x86_64.rpm
    sha:36c0a66c80169afeaf0e6c72e07f7a8ef19e85fdd618ed0f6a513e408ddfb6dc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.