Release date:
2026-07-22 10:22:54 UTC
Description:
* SECURITY UPDATE: buffer overrun and uninitialized memory disclosure in
the script engine when variable length and copy passes disagree
- debian/patches/CVE-2026-42533.patch: add e->end buffer boundary checks via
ngx_http_script_check_length() to all script copy operations and to
direct script usage in the proxy, fastcgi, scgi, uwsgi, grpc, index
and try_files modules
- CVE-2026-42533
Updated packages:
-
nginx1.23_1.23.4-1~trixie+tuxcare.els13_amd64.deb
sha:70e2dea9c84973bb6a114b0f6f54d3b0640c85d7
-
nginx1.23_1.23.4-1~trixie+tuxcare.els13_arm64.deb
sha:84e4271204ade1bb3a7be37ce9089de91151fa42
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.