[CLSA-2026:1784712003] Fix CVE(s): CVE-2026-42533
Type:
security
Severity:
Low
Release date:
2026-07-22 09:20:28 UTC
Description:
* SECURITY UPDATE: Buffer overrun and uninitialized memory read in the script engine when evaluating variables with regex captures - debian/patches/CVE-2026-42533.patch: add buffer-overrun protection to script copy operations via the e->end guard and fix stale regex captures in ngx_http_script.c, ngx_http_variables.c and the proxy, fastcgi, scgi, uwsgi, grpc, index and try_files modules; also add the matching buffer-overrun protection to the access log script copy operations in ngx_http_log_module.c and ngx_stream_log_module.c - CVE-2026-42533 * SECURITY UPDATE: Uninitialized memory read caused by stale regex captures in the slice module - debian/patches/CVE-2026-42533.patch: update r->ncaptures when ngx_http_regex_exec() reallocates r->captures so a later unnamed capture does not read uninitialized memory - CVE-2026-60005
CVEs fixed:
Updated packages:
  • nginx1.25_1.25.5-1~trixie+tuxcare.els16_amd64.deb
    sha:a92758cd8cc13f4988c1bf6b62109acb813534f9
  • nginx1.25_1.25.5-1~trixie+tuxcare.els16_arm64.deb
    sha:951b2052d98a8a4943f6fec31538cc1dec913535
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.