[CLSA-2026:1785845612] Fix CVE(s): CVE-2026-42055
Type:
security
Severity:
Important
Release date:
2026-08-04 12:13:44 UTC
Description:
* SECURITY UPDATE: Heap buffer overflow in ngx_http_grpc_module when proxying oversized headers to a gRPC/HTTP/2 upstream - debian/patches/CVE-2026-42055.patch: reject request line and header fields longer than NGX_HTTP_V2_MAX_FIELD in ngx_http_grpc_create_request to prevent buffer overrun when large_client_header_buffers exceeds 2 megabytes and ignore_invalid_headers is off - CVE-2026-42055
CVEs fixed:
Updated packages:
  • libnginx-mod-http-auth-pam_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb
    sha:38954498ed6719cb122a7af7b10c7d010a26f5cb
  • libnginx-mod-http-cache-purge_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb
    sha:6709c72ededd5dd7216c840fac73b5e25cc17eda
  • libnginx-mod-http-dav-ext_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb
    sha:38ff4727765774fe9c41fd923e000ab18a79417d
  • libnginx-mod-http-echo_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb
    sha:20479a21cb162273736481b90704d18e6c88e8f8
  • libnginx-mod-http-fancyindex_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb
    sha:eddcea0bbf88638bc38f5a23554529b36ffeb87e
  • libnginx-mod-http-geoip_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb
    sha:fd058a14455a890370bef14252859af56c5f40d8
  • libnginx-mod-http-headers-more-filter_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb
    sha:9921d5d8ced0afe9cfbadf2f6e7c9aa2fdd44364
  • libnginx-mod-http-image-filter_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb
    sha:a72dac315813cf099decbce74d34be742ddf2f74
  • libnginx-mod-http-lua_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb
    sha:25dc53b69f65675a8d0cd4ec7a87f5fa2580cfb5
  • libnginx-mod-http-ndk_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb
    sha:13e0d87c5e3de9567fe47865a70698f68d78258c
  • libnginx-mod-http-perl_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb
    sha:068737687d36e7a2899963e4866b6339866e6174
  • libnginx-mod-http-subs-filter_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb
    sha:423e8213f6c4663153880aeeb0192b28c4470c90
  • libnginx-mod-http-uploadprogress_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb
    sha:5c9456d4140c52ddebe5d69dbcc15b7571bc10ed
  • libnginx-mod-http-upstream-fair_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb
    sha:9419da098fe6b681adbc823f202933a68da2e0a8
  • libnginx-mod-http-xslt-filter_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb
    sha:e51ce5bb438377163779fe02025c09da91682bc7
  • libnginx-mod-mail_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb
    sha:7e340c0b02fe234dbab9c3ca8054324d43cf69da
  • libnginx-mod-nchan_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb
    sha:1bb2196014abdfddc083a08ccdc7c1e24737e390
  • libnginx-mod-rtmp_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb
    sha:e9ced65fbb418b205e429af9f77338eae0094d65
  • libnginx-mod-stream_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb
    sha:fe72f27268c93d2775346d7c53543c52002f2e4e
  • nginx_1.14.2-2+deb10u5+tuxcare.els4_all.deb
    sha:297ffe18fca29860c6e201afe9b0277b96fc6787
  • nginx-common_1.14.2-2+deb10u5+tuxcare.els4_all.deb
    sha:cf731ba643ce11b73e6da3aed78db44c13256ce7
  • nginx-doc_1.14.2-2+deb10u5+tuxcare.els4_all.deb
    sha:9a81b45f11cf89b9f6e503e83e02148ec84797a1
  • nginx-extras_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb
    sha:acc8a1746e5128fae1480dcbb235ebe216f0486e
  • nginx-full_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb
    sha:7061ac923d25d1e24d672dbb71a30fd1c659e997
  • nginx-light_1.14.2-2+deb10u5+tuxcare.els4_amd64.deb
    sha:2cdc5a221068acef28509ff45cb7f28386f8a64c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.