[CLSA-2026:1784800112] nginx: Fix of CVE-2026-42533
Type:
security
Severity:
Low
Release date:
2026-07-23 09:48:58 UTC
Description:
- CVE-2026-42533: add script engine buffer-overrun protection to fix heap overflow and info-leak via regex map capture variables
CVEs fixed:
Updated packages:
  • nginx-1.14.1-9.module_el8.4.0+2449+d976c26a.tuxcare.els12.x86_64.rpm
    sha:d410e943cf0fb6541f122598d51d0d7a9ab7a8032bc2f2102342ac9d0ee52a3a
  • nginx-all-modules-1.14.1-9.module_el8.4.0+2449+d976c26a.tuxcare.els12.noarch.rpm
    sha:eb22731dda5bc26d1b13629ca9d5e7c5cbd22bac4f73c4a52f5e94476a2f64f8
  • nginx-filesystem-1.14.1-9.module_el8.4.0+2449+d976c26a.tuxcare.els12.noarch.rpm
    sha:e125542c2902748908143a4a3583e6191e3ceaea1659152688cd1e0d10a7d642
  • nginx-mod-http-image-filter-1.14.1-9.module_el8.4.0+2449+d976c26a.tuxcare.els12.x86_64.rpm
    sha:b50db820ad5e6bc678155f069b3f32bce827d807d95cc18ca54d4925501d5d88
  • nginx-mod-http-perl-1.14.1-9.module_el8.4.0+2449+d976c26a.tuxcare.els12.x86_64.rpm
    sha:1e090fa8c31cdd1fb63fbb7e597494049aa3bae4243cda8fedbecd7b0291967e
  • nginx-mod-http-xslt-filter-1.14.1-9.module_el8.4.0+2449+d976c26a.tuxcare.els12.x86_64.rpm
    sha:d2fb338682033b9a7e36ae6ccedb1ccf3271cfcb99bf309962694a07bae2c1ec
  • nginx-mod-mail-1.14.1-9.module_el8.4.0+2449+d976c26a.tuxcare.els12.x86_64.rpm
    sha:931a4674ebbc18aeaddf56a9cff374a30086218d0b5eaee98daf76618732702e
  • nginx-mod-stream-1.14.1-9.module_el8.4.0+2449+d976c26a.tuxcare.els12.x86_64.rpm
    sha:6159d2b461061abc6f1494526f210e78208841ddee6280bb8474a381d5618fad
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.