[CLSA-2026:1785752201] Fix CVE(s): CVE-2026-40460, CVE-2026-42055, CVE-2026-56434, CVE-2026-60005
Type:
security
Severity:
Important
Release date:
2026-08-03 10:17:01 UTC
Description:
* SECURITY UPDATE: source address spoofing over HTTP/3, where a client that migrated to a new address had that address assigned to newly created QUIC streams before the address was validated, allowing an attacker to bypass authorization or rate limiting - debian/patches/CVE-2026-40460.patch: assign the connection path only once the path is validated, and drop the assignment from the backup path restore branch in src/event/quic/ngx_event_quic_migration.c - CVE-2026-40460 * SECURITY UPDATE: heap buffer overflow when proxying to a gRPC upstream, where ngx_http_grpc_create_request() reserved a fixed NGX_HTTP_V2_INT_OCTETS prefix for each HPACK field length without bounding the length of the field itself - debian/patches/CVE-2026-42055.patch: reject the request when the method, URI, host, or any header name or value exceeds NGX_HTTP_V2_MAX_FIELD in src/http/modules/ngx_http_grpc_module.c - only the gRPC half of the upstream fix applies here; the HTTP/2 proxy module does not exist in nginx 1.26, where proxy_http_version accepts only 1.0 and 1.1 - CVE-2026-42055 * SECURITY UPDATE: use-after-free during subrequest finalization, where a subrequest that was posted twice could be finalized twice and decrement r->main->count once too often, reachable through the SSI filter during unbuffered proxying - debian/patches/CVE-2026-56434.patch: skip posting a request that is already on the posted_requests list, and reset r->write_event_handler to the no-op handler while an active subrequest is being finalized in src/http/ngx_http_request.c - CVE-2026-56434 * SECURITY UPDATE: uninitialized memory read via stale regex captures, where ngx_http_regex_exec() reallocated r->captures without resetting r->ncaptures when the regex did not match, so a later unnamed capture read past the initialized part of the array - debian/patches/CVE-2026-60005.patch: reset r->ncaptures together with r->realloc_captures in src/http/ngx_http_variables.c - CVE-2026-60005
Updated packages:
  • libnginx-mod-http-geoip-1.26_1.26.3-3~trixie+tuxcare.els13_amd64.deb
    sha:4b37224e9e0ec2a9dc9cf306891973870936253f
  • libnginx-mod-http-image-filter-1.26_1.26.3-3~trixie+tuxcare.els13_amd64.deb
    sha:5a8b3b773f27b859c4161839ccdd9b224fa5ffa9
  • libnginx-mod-http-perl-1.26_1.26.3-3~trixie+tuxcare.els13_amd64.deb
    sha:395369015b01baaa2871f0b8830df19f14cec9e1
  • libnginx-mod-http-xslt-filter-1.26_1.26.3-3~trixie+tuxcare.els13_amd64.deb
    sha:f48dae7f66d63c34e690d2a1f311ca68f634fd2b
  • libnginx-mod-mail-1.26_1.26.3-3~trixie+tuxcare.els13_amd64.deb
    sha:1ee43175d05438d52d76ead90c77aa54b2b0f79f
  • libnginx-mod-stream-1.26_1.26.3-3~trixie+tuxcare.els13_amd64.deb
    sha:9f75b5f6b0569e36d8777394c7a7ff8edd4862ae
  • libnginx-mod-stream-geoip-1.26_1.26.3-3~trixie+tuxcare.els13_amd64.deb
    sha:3b8b0f75459a5882eca2884a423e2a0a1568ffaa
  • nginx1.26_1.26.3-3~trixie+tuxcare.els13_amd64.deb
    sha:fa19ea0132dd7355108bc2fb5825a829263b7f4a
  • nginx1.26-common_1.26.3-3~trixie+tuxcare.els13_all.deb
    sha:b385b6affdbaa9ae9524034bc9afd52b78391cea
  • nginx1.26-dev_1.26.3-3~trixie+tuxcare.els13_all.deb
    sha:46944098f28453888f99526e86ed88ed558f294e
  • nginx1.26-doc_1.26.3-3~trixie+tuxcare.els13_all.deb
    sha:78802bf66140f078ed56c435574b59df007485d7
  • libnginx-mod-http-geoip-1.26_1.26.3-3~trixie+tuxcare.els13_arm64.deb
    sha:77295ca91b607c91dcbc9ab796ddd744a9777df0
  • libnginx-mod-http-image-filter-1.26_1.26.3-3~trixie+tuxcare.els13_arm64.deb
    sha:55e19582e85f0c2bd513b5823bd2f40b998601ce
  • libnginx-mod-http-perl-1.26_1.26.3-3~trixie+tuxcare.els13_arm64.deb
    sha:0fee15b2ca6bb20919eb5dc250a428a5e46be1ef
  • libnginx-mod-http-xslt-filter-1.26_1.26.3-3~trixie+tuxcare.els13_arm64.deb
    sha:72244851f909afd4901499eec8d55c0c8adbcfef
  • libnginx-mod-mail-1.26_1.26.3-3~trixie+tuxcare.els13_arm64.deb
    sha:90c80ce3ced1ca2ec8b73d79605d870ada96a104
  • libnginx-mod-stream-1.26_1.26.3-3~trixie+tuxcare.els13_arm64.deb
    sha:c471c5764b852b8f02abf1346185060ca2432be9
  • libnginx-mod-stream-geoip-1.26_1.26.3-3~trixie+tuxcare.els13_arm64.deb
    sha:21bf262ec8f161b3c17581f2e0bc72c2989943f1
  • nginx1.26_1.26.3-3~trixie+tuxcare.els13_arm64.deb
    sha:26e643c124c7bc85ec24ee3af53798e464dee86e
  • nginx1.26-common_1.26.3-3~trixie+tuxcare.els13_all.deb
    sha:b385b6affdbaa9ae9524034bc9afd52b78391cea
  • nginx1.26-dev_1.26.3-3~trixie+tuxcare.els13_all.deb
    sha:46944098f28453888f99526e86ed88ed558f294e
  • nginx1.26-doc_1.26.3-3~trixie+tuxcare.els13_all.deb
    sha:78802bf66140f078ed56c435574b59df007485d7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.