[CLSA-2026:1785922957] nginx: Fix of 4 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-08-05 09:42:52 UTC
Description:
- CVE-2026-40701: fix resolver use-after-free in OCSP; the resolve context was leaked when a client SSL connection was terminated while resolving an OCSP responder, so completion of the resolve touched freed memory - CVE-2025-53859: fix buffer over-read in ngx_mail_smtp_module; login and password storage could be left in an inconsistent state after base64 decoding errors in the plain/login/cram-md5 auth methods - CVE-2026-28753: validate the host name resolved from the client address against the character set of RFC 1034 section 3.5, preventing CRLF injection into auth_http and smtp proxy requests - CVE-2026-42934: fix buffer over-read in ngx_http_charset_module recode_from_utf8(); pass the saved byte count rather than the last saved index to ngx_utf8_decode() and advance past the whole saved sequence on invalid UTF-8
Updated packages:
  • nginx-1.20.1-14.el9_2.1.alma.1.tuxcare.els13.x86_64.rpm
    sha:350ade4fdb83ea1c6fe4465d234f861745903df435fa5070d3d82ef155e351c7
  • nginx-all-modules-1.20.1-14.el9_2.1.alma.1.tuxcare.els13.noarch.rpm
    sha:e8489ecd3ebb768a4be6dd5435a3d8bbdeb57c0888a2632c0eed3a5d4f24b21a
  • nginx-core-1.20.1-14.el9_2.1.alma.1.tuxcare.els13.x86_64.rpm
    sha:c3def4ce4c7c7f5ba1aacf65076d65a6b828bad46a3739aedf1a734341c940cb
  • nginx-filesystem-1.20.1-14.el9_2.1.alma.1.tuxcare.els13.noarch.rpm
    sha:4fe12a4eed3cda4254fc08b94c3d3b41b5af8662fe4a469e810568a1340cd9e9
  • nginx-mod-devel-1.20.1-14.el9_2.1.alma.1.tuxcare.els13.x86_64.rpm
    sha:dccc00ff1e9c2715d584f4b482c99d84ebd0f72466dc4198fa923402f06dc1a8
  • nginx-mod-http-image-filter-1.20.1-14.el9_2.1.alma.1.tuxcare.els13.x86_64.rpm
    sha:7bffe66a93afef8267ced60715140b146c29d766a811b378a30a55ff952afb30
  • nginx-mod-http-perl-1.20.1-14.el9_2.1.alma.1.tuxcare.els13.x86_64.rpm
    sha:857cb3370e6e5943690b0add8801b0182128560a620716d37ee5e7b5b9dc75d2
  • nginx-mod-http-xslt-filter-1.20.1-14.el9_2.1.alma.1.tuxcare.els13.x86_64.rpm
    sha:6217c8e92b667f8fa7418d89838838670ee4ede03e7735c71c75f94becc92fe7
  • nginx-mod-mail-1.20.1-14.el9_2.1.alma.1.tuxcare.els13.x86_64.rpm
    sha:0e46e901c8beb127a2cc1d8c59f4453d16a91c904c5f524e18cc4b8fe5974e40
  • nginx-mod-stream-1.20.1-14.el9_2.1.alma.1.tuxcare.els13.x86_64.rpm
    sha:ce25f2cd01878d9128a9c152b93ccf8d7184eaf135168f4a295e8b9c15e1d862
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.