Release date:
2026-07-22 09:39:31 UTC
Description:
* SECURITY UPDATE: Buffer overrun and uninitialized memory read in the
script engine when evaluating variables with regex captures
- debian/patches/CVE-2026-42533.patch: add buffer-overrun protection to
script copy operations via the e->end guard and fix stale regex
captures in ngx_http_script.c, ngx_http_variables.c and the proxy,
fastcgi, scgi, uwsgi, grpc, index and try_files modules; also add the
matching buffer-overrun protection to the access log script copy
operations in ngx_http_log_module.c and ngx_stream_log_module.c
- CVE-2026-42533
* SECURITY UPDATE: Uninitialized memory read caused by stale regex
captures in the slice module
- debian/patches/CVE-2026-42533.patch: update r->ncaptures when
ngx_http_regex_exec() reallocates r->captures so a later unnamed
capture does not read uninitialized memory
- CVE-2026-60005
Updated packages:
-
nginx1.25_1.25.5-1~bookworm+tuxcare.els16_amd64.deb
sha:f87f651c81acaefdf5a8c9ac06bc16191e2e6306
-
nginx1.25_1.25.5-1~bookworm+tuxcare.els16_arm64.deb
sha:653c2c9b1cfe5cb0ca8a55ccbc58b30c39398c1b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.