[CLSA-2026:1785753373] Fix CVE(s): CVE-2026-40460, CVE-2026-42055, CVE-2026-56434, CVE-2026-60005
Type:
security
Severity:
Important
Release date:
2026-08-03 10:36:28 UTC
Description:
* SECURITY UPDATE: source address spoofing over HTTP/3, where a client that migrated to a new address had that address assigned to newly created QUIC streams before the address was validated, allowing an attacker to bypass authorization or rate limiting - debian/patches/CVE-2026-40460.patch: assign the connection path only once the path is validated, and drop the assignment from the backup path restore branch in src/event/quic/ngx_event_quic_migration.c - CVE-2026-40460 * SECURITY UPDATE: heap buffer overflow when proxying to a gRPC upstream, where ngx_http_grpc_create_request() reserved a fixed NGX_HTTP_V2_INT_OCTETS prefix for each HPACK field length without bounding the length of the field itself - debian/patches/CVE-2026-42055.patch: reject the request when the method, URI, host, or any header name or value exceeds NGX_HTTP_V2_MAX_FIELD in src/http/modules/ngx_http_grpc_module.c - only the gRPC half of the upstream fix applies here; the HTTP/2 proxy module does not exist in nginx 1.26, where proxy_http_version accepts only 1.0 and 1.1 - CVE-2026-42055 * SECURITY UPDATE: use-after-free during subrequest finalization, where a subrequest that was posted twice could be finalized twice and decrement r->main->count once too often, reachable through the SSI filter during unbuffered proxying - debian/patches/CVE-2026-56434.patch: skip posting a request that is already on the posted_requests list, and reset r->write_event_handler to the no-op handler while an active subrequest is being finalized in src/http/ngx_http_request.c - CVE-2026-56434 * SECURITY UPDATE: uninitialized memory read via stale regex captures, where ngx_http_regex_exec() reallocated r->captures without resetting r->ncaptures when the regex did not match, so a later unnamed capture read past the initialized part of the array - debian/patches/CVE-2026-60005.patch: reset r->ncaptures together with r->realloc_captures in src/http/ngx_http_variables.c - CVE-2026-60005
Updated packages:
  • libnginx-mod-http-geoip-1.26_1.26.3-3~bookworm+tuxcare.els13_amd64.deb
    sha:64fa8daffe7135b09b808e22d3af3cf399ec3969
  • libnginx-mod-http-image-filter-1.26_1.26.3-3~bookworm+tuxcare.els13_amd64.deb
    sha:a62f4364f7524a75ca54798ec8f78df09867d937
  • libnginx-mod-http-perl-1.26_1.26.3-3~bookworm+tuxcare.els13_amd64.deb
    sha:e6051cd84d0a77cc74e7c77219135d542bf4063c
  • libnginx-mod-http-xslt-filter-1.26_1.26.3-3~bookworm+tuxcare.els13_amd64.deb
    sha:3d26da2a9de5174a82283a9324af9f2f8158e6c2
  • libnginx-mod-mail-1.26_1.26.3-3~bookworm+tuxcare.els13_amd64.deb
    sha:edd6a5e9c86205abfa44178f0b5f8e324f2c684c
  • libnginx-mod-stream-1.26_1.26.3-3~bookworm+tuxcare.els13_amd64.deb
    sha:1824f03399adb763594c45094441021c6d3ea7db
  • libnginx-mod-stream-geoip-1.26_1.26.3-3~bookworm+tuxcare.els13_amd64.deb
    sha:767e8c25037d078f8550724f8f7ede3d1456138e
  • nginx1.26_1.26.3-3~bookworm+tuxcare.els13_amd64.deb
    sha:d0320a3ebb695f21dd4fa50f4f1ec9de63f2704a
  • nginx1.26-common_1.26.3-3~bookworm+tuxcare.els13_all.deb
    sha:98b5752c70eb6b75b682f3a077cbfa2a3679ff11
  • nginx1.26-dev_1.26.3-3~bookworm+tuxcare.els13_all.deb
    sha:1a57cbd663c93b679750eaf1e6d3a91e991ec2a4
  • nginx1.26-doc_1.26.3-3~bookworm+tuxcare.els13_all.deb
    sha:a80ecbe1c57a185ddea238f68497b62c26b9c259
  • libnginx-mod-http-geoip-1.26_1.26.3-3~bookworm+tuxcare.els13_arm64.deb
    sha:2464b51c31adf1a6b56a34ec83862e0381f9569d
  • libnginx-mod-http-image-filter-1.26_1.26.3-3~bookworm+tuxcare.els13_arm64.deb
    sha:cb5e1bb139b1584c610183ca295ca2d11c776eae
  • libnginx-mod-http-perl-1.26_1.26.3-3~bookworm+tuxcare.els13_arm64.deb
    sha:1ea03654758d95104e1c7b6e072dbe8d288a107d
  • libnginx-mod-http-xslt-filter-1.26_1.26.3-3~bookworm+tuxcare.els13_arm64.deb
    sha:043972ff045d277ea4c1ca4044f4c00632794d61
  • libnginx-mod-mail-1.26_1.26.3-3~bookworm+tuxcare.els13_arm64.deb
    sha:f5297d38f550f20c60d6c7bd8cd9554fcebb9be2
  • libnginx-mod-stream-1.26_1.26.3-3~bookworm+tuxcare.els13_arm64.deb
    sha:35d452b3968a7d7dc24753ec6d1cc33b00dc72c3
  • libnginx-mod-stream-geoip-1.26_1.26.3-3~bookworm+tuxcare.els13_arm64.deb
    sha:10d8c20f70c86f1b52bc28ce529456d74eaa2be1
  • nginx1.26_1.26.3-3~bookworm+tuxcare.els13_arm64.deb
    sha:08595db10c36cef97426a22f2990905e4f6e551b
  • nginx1.26-common_1.26.3-3~bookworm+tuxcare.els13_all.deb
    sha:98b5752c70eb6b75b682f3a077cbfa2a3679ff11
  • nginx1.26-dev_1.26.3-3~bookworm+tuxcare.els13_all.deb
    sha:1a57cbd663c93b679750eaf1e6d3a91e991ec2a4
  • nginx1.26-doc_1.26.3-3~bookworm+tuxcare.els13_all.deb
    sha:a80ecbe1c57a185ddea238f68497b62c26b9c259
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.