[CLSA-2026:1784709149] Fix CVE(s): CVE-2026-42533
Type:
security
Severity:
Low
Release date:
2026-07-22 08:32:53 UTC
Description:
* SECURITY UPDATE: buffer overrun and uninitialized memory disclosure in the script engine when variable length and copy passes disagree - debian/patches/CVE-2026-42533.patch: add e->end buffer boundary checks via ngx_http_script_check_length() to all script copy operations and to direct script usage in the proxy, fastcgi, scgi, uwsgi, grpc, index and try_files modules - CVE-2026-42533
CVEs fixed:
Updated packages:
  • nginx1.23_1.23.4-1~bookworm+tuxcare.els13_amd64.deb
    sha:37b9ffe6b6679a504ad29ad97f26fef041280d66
  • nginx1.23_1.23.4-1~bookworm+tuxcare.els13_arm64.deb
    sha:fc5181319188b8b79cce6c8b91e0ce3bf147d5dd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.