[CLSA-2026:1790180493] nginx: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2026-09-23 16:21:47 UTC
Description:
- CVE-2026-27651: fix null pointer dereference in ngx_mail_auth_http_module when clearing the password in auth http requests with CRAM-MD5/APOP - CVE-2026-27654: fix heap buffer overflow in ngx_http_dav_module when a COPY/MOVE destination URI is shorter than the location alias - CVE-2026-27654: also require the COPY/MOVE Destination to match the aliased location prefix, and tighten ngx_http_map_uri_to_path() accordingly - CVE-2026-27784: fix integer overflow in ngx_http_mp4_module atom entry count validation on 32-bit platforms
Updated packages:
  • nginx-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
    sha:b2e06dae4f06e9361590a15794ba267f01bb1e65bbb243441d94ebc60f9ac2e1
  • nginx-all-modules-1.20.1-10.el7.tuxcare.els9.noarch.rpm
    sha:53aab7e57ae717050242fc34c2ca0756b7051572f713ac4b4b85bfa2701b3c67
  • nginx-filesystem-1.20.1-10.el7.tuxcare.els9.noarch.rpm
    sha:61fe172be8248d27794113b2508dea729c4acc22031fa4d6bb51b550be160e22
  • nginx-mod-devel-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
    sha:c1a03a86f80f7d46bc0c93109038213e5fbf4564d0d90b00c2c0815c550152fd
  • nginx-mod-http-image-filter-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
    sha:4feb22008428f4204453fe60f6fd9cdd09f8c1befe5c99e4dfe50b5c08c64b10
  • nginx-mod-http-perl-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
    sha:ab65f52b7eeba6fa0730d4e99e52e6eddda5857639fc2a21e38e7316dd43da96
  • nginx-mod-http-xslt-filter-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
    sha:7022303303588bc7b4c8ba494c620a58470cc29ea826419c9daa57641a3d25e0
  • nginx-mod-mail-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
    sha:4dec80d2be41674c9bedfd79bdb8d1b2b2c786f3edf455797c167644c74f0d00
  • nginx-mod-stream-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
    sha:64aa175dac415edec2fbaab52b4499a7ccccc8633c52593d20540fbfc1a7299c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.