Release date:
2026-08-05 09:42:52 UTC
Description:
- CVE-2026-40701: fix resolver use-after-free in OCSP; the resolve
context was leaked when a client SSL connection was terminated while
resolving an OCSP responder, so completion of the resolve touched
freed memory
- CVE-2025-53859: fix buffer over-read in ngx_mail_smtp_module; login
and password storage could be left in an inconsistent state after
base64 decoding errors in the plain/login/cram-md5 auth methods
- CVE-2026-28753: validate the host name resolved from the client
address against the character set of RFC 1034 section 3.5,
preventing CRLF injection into auth_http and smtp proxy requests
- CVE-2026-42934: fix buffer over-read in ngx_http_charset_module
recode_from_utf8(); pass the saved byte count rather than the last
saved index to ngx_utf8_decode() and advance past the whole saved
sequence on invalid UTF-8
Updated packages:
-
nginx-1.20.1-14.el9_2.1.alma.1.tuxcare.els13.x86_64.rpm
sha:350ade4fdb83ea1c6fe4465d234f861745903df435fa5070d3d82ef155e351c7
-
nginx-all-modules-1.20.1-14.el9_2.1.alma.1.tuxcare.els13.noarch.rpm
sha:e8489ecd3ebb768a4be6dd5435a3d8bbdeb57c0888a2632c0eed3a5d4f24b21a
-
nginx-core-1.20.1-14.el9_2.1.alma.1.tuxcare.els13.x86_64.rpm
sha:c3def4ce4c7c7f5ba1aacf65076d65a6b828bad46a3739aedf1a734341c940cb
-
nginx-filesystem-1.20.1-14.el9_2.1.alma.1.tuxcare.els13.noarch.rpm
sha:4fe12a4eed3cda4254fc08b94c3d3b41b5af8662fe4a469e810568a1340cd9e9
-
nginx-mod-devel-1.20.1-14.el9_2.1.alma.1.tuxcare.els13.x86_64.rpm
sha:dccc00ff1e9c2715d584f4b482c99d84ebd0f72466dc4198fa923402f06dc1a8
-
nginx-mod-http-image-filter-1.20.1-14.el9_2.1.alma.1.tuxcare.els13.x86_64.rpm
sha:7bffe66a93afef8267ced60715140b146c29d766a811b378a30a55ff952afb30
-
nginx-mod-http-perl-1.20.1-14.el9_2.1.alma.1.tuxcare.els13.x86_64.rpm
sha:857cb3370e6e5943690b0add8801b0182128560a620716d37ee5e7b5b9dc75d2
-
nginx-mod-http-xslt-filter-1.20.1-14.el9_2.1.alma.1.tuxcare.els13.x86_64.rpm
sha:6217c8e92b667f8fa7418d89838838670ee4ede03e7735c71c75f94becc92fe7
-
nginx-mod-mail-1.20.1-14.el9_2.1.alma.1.tuxcare.els13.x86_64.rpm
sha:0e46e901c8beb127a2cc1d8c59f4453d16a91c904c5f524e18cc4b8fe5974e40
-
nginx-mod-stream-1.20.1-14.el9_2.1.alma.1.tuxcare.els13.x86_64.rpm
sha:ce25f2cd01878d9128a9c152b93ccf8d7184eaf135168f4a295e8b9c15e1d862
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.