Release date:
2026-09-23 16:21:19 UTC
Description:
- CVE-2026-27651: fix null pointer dereference in ngx_mail_auth_http_module
when clearing the password in auth http requests with CRAM-MD5/APOP
- CVE-2026-27654: fix heap buffer overflow in ngx_http_dav_module when a
COPY/MOVE destination URI is shorter than the location alias
- CVE-2026-27654: also require the COPY/MOVE Destination to match the aliased
location prefix, and tighten ngx_http_map_uri_to_path() accordingly
- CVE-2026-27784: fix integer overflow in ngx_http_mp4_module atom entry
count validation on 32-bit platforms
Updated packages:
-
nginx-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
sha:46f0c69875dfd750fd8a663af2507a16f6b0f725af73121e5996557c1c09f767
-
nginx-all-modules-1.20.1-10.el7.tuxcare.els9.noarch.rpm
sha:c53d229fbf3341437cf0d673d8fd98dcb6cc41d1e831eb5002161be33d431d42
-
nginx-filesystem-1.20.1-10.el7.tuxcare.els9.noarch.rpm
sha:48db8bae8ce694b8c879300834e59409e78d0513d8f4361012143b58321d4d0b
-
nginx-mod-devel-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
sha:907f8b1f7417f73c0baa1bb86ee8fbd6a3ed2418881a7f70c14e74462f1b5f9f
-
nginx-mod-http-image-filter-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
sha:f4ac569eef3e2dcc9ce70f1cb11e6104947166de62508f712ee5aa5aa7c40e4d
-
nginx-mod-http-perl-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
sha:1a6c95458537a419474948cd58cd5f78586f01f91714d95e8d778d5e77810cbc
-
nginx-mod-http-xslt-filter-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
sha:b830e0b98fb336d42bf97e565b0ed0f4b720fd743d09db7ae6fa5fe9c1e1b0ac
-
nginx-mod-mail-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
sha:55e6822cacf020811ddedaf915d6d943c8837cb4105828227fcd6ce7bc436bbc
-
nginx-mod-stream-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
sha:6c52ddf6baf00bdf2f2a14f9901d5260ebeff99efb68e4cbc6526bba21d7f3fc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.