[CLSA-2026:1784713147] Fix CVE(s): CVE-2026-42533
Type:
security
Severity:
Low
Release date:
2026-07-22 09:39:31 UTC
Description:
* SECURITY UPDATE: Buffer overrun and uninitialized memory read in the script engine when evaluating variables with regex captures - debian/patches/CVE-2026-42533.patch: add buffer-overrun protection to script copy operations via the e->end guard and fix stale regex captures in ngx_http_script.c, ngx_http_variables.c and the proxy, fastcgi, scgi, uwsgi, grpc, index and try_files modules; also add the matching buffer-overrun protection to the access log script copy operations in ngx_http_log_module.c and ngx_stream_log_module.c - CVE-2026-42533 * SECURITY UPDATE: Uninitialized memory read caused by stale regex captures in the slice module - debian/patches/CVE-2026-42533.patch: update r->ncaptures when ngx_http_regex_exec() reallocates r->captures so a later unnamed capture does not read uninitialized memory - CVE-2026-60005
CVEs fixed:
Updated packages:
  • nginx1.25_1.25.5-1~bookworm+tuxcare.els16_amd64.deb
    sha:f87f651c81acaefdf5a8c9ac06bc16191e2e6306
  • nginx1.25_1.25.5-1~bookworm+tuxcare.els16_arm64.deb
    sha:653c2c9b1cfe5cb0ca8a55ccbc58b30c39398c1b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.