[CLSA-2026:1784713367] Fix CVE(s): CVE-2026-42533
Type:
security
Severity:
Low
Release date:
2026-07-22 09:43:11 UTC
Description:
* SECURITY UPDATE: buffer overrun in the script engine when a regex capture or non-cacheable variable changes size between the length and copy passes, as reachable via the map directive with a regex-derived capture - debian/patches/CVE-2026-42533.patch: add an e->end buffer-end pointer and an ngx_http_script_check_length() bounds guard to the script copy operations in src/http/ngx_http_script.{c,h} and src/stream/ngx_stream_script.{c,h}; add the missing i+1 < v->len bounds check before testing the byte after '$' in ngx_http_compile_complex_value and ngx_stream_compile_complex_value - CVE-2026-42533
CVEs fixed:
Updated packages:
  • nginx1.21_1.21.6-1~trixie+tuxcare.els11_amd64.deb
    sha:3ccab9ffaf61028217adcddc9a3c4cdcc40d84a9
  • nginx1.21_1.21.6-1~trixie+tuxcare.els11_arm64.deb
    sha:4acff6eec2332c1493a7b51c1ea5bebb88ae2810
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.