[CLSA-2026:1784715749] Fix CVE(s): CVE-2026-42533
Type:
security
Severity:
Low
Release date:
2026-07-22 10:22:54 UTC
Description:
* SECURITY UPDATE: buffer overrun and uninitialized memory disclosure in the script engine when variable length and copy passes disagree - debian/patches/CVE-2026-42533.patch: add e->end buffer boundary checks via ngx_http_script_check_length() to all script copy operations and to direct script usage in the proxy, fastcgi, scgi, uwsgi, grpc, index and try_files modules - CVE-2026-42533
CVEs fixed:
Updated packages:
  • nginx1.23_1.23.4-1~trixie+tuxcare.els13_amd64.deb
    sha:70e2dea9c84973bb6a114b0f6f54d3b0640c85d7
  • nginx1.23_1.23.4-1~trixie+tuxcare.els13_arm64.deb
    sha:84e4271204ade1bb3a7be37ce9089de91151fa42
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.