Release date:
2026-07-22 09:20:28 UTC
Description:
* SECURITY UPDATE: Buffer overrun and uninitialized memory read in the
script engine when evaluating variables with regex captures
- debian/patches/CVE-2026-42533.patch: add buffer-overrun protection to
script copy operations via the e->end guard and fix stale regex
captures in ngx_http_script.c, ngx_http_variables.c and the proxy,
fastcgi, scgi, uwsgi, grpc, index and try_files modules; also add the
matching buffer-overrun protection to the access log script copy
operations in ngx_http_log_module.c and ngx_stream_log_module.c
- CVE-2026-42533
* SECURITY UPDATE: Uninitialized memory read caused by stale regex
captures in the slice module
- debian/patches/CVE-2026-42533.patch: update r->ncaptures when
ngx_http_regex_exec() reallocates r->captures so a later unnamed
capture does not read uninitialized memory
- CVE-2026-60005
Updated packages:
-
nginx1.25_1.25.5-1~trixie+tuxcare.els16_amd64.deb
sha:a92758cd8cc13f4988c1bf6b62109acb813534f9
-
nginx1.25_1.25.5-1~trixie+tuxcare.els16_arm64.deb
sha:951b2052d98a8a4943f6fec31538cc1dec913535
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.