Release date:
2026-07-22 08:32:53 UTC
Description:
* SECURITY UPDATE: buffer overrun and uninitialized memory disclosure in
the script engine when variable length and copy passes disagree
- debian/patches/CVE-2026-42533.patch: add e->end buffer boundary checks via
ngx_http_script_check_length() to all script copy operations and to
direct script usage in the proxy, fastcgi, scgi, uwsgi, grpc, index
and try_files modules
- CVE-2026-42533
Updated packages:
-
nginx1.23_1.23.4-1~bookworm+tuxcare.els13_amd64.deb
sha:37b9ffe6b6679a504ad29ad97f26fef041280d66
-
nginx1.23_1.23.4-1~bookworm+tuxcare.els13_arm64.deb
sha:fc5181319188b8b79cce6c8b91e0ce3bf147d5dd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.