Release date:
2026-08-17 16:02:42 UTC
Description:
* SECURITY UPDATE: Heap buffer overflow in njs proxy URL credential decoding
- debian/patches/CVE-2026-8711.patch: size decoded username and password
buffers from their encoded input lengths and add a regression test
- CVE-2026-8711
* SECURITY UPDATE: Use-after-free caused by duplicate subrequest finalization
- debian/patches/CVE-2026-56434.patch: prevent duplicate request posting and
reset the write event handler during active subrequest finalization
- CVE-2026-56434
* SECURITY UPDATE: Heap buffer overflow from oversized gRPC headers
- debian/patches/CVE-2026-42055.patch: enforce HTTP/2 field length limits
when constructing gRPC requests
- CVE-2026-42055
* SECURITY UPDATE: Buffer over-read while recoding invalid UTF-8 sequences
- debian/patches/CVE-2026-48142.patch: advance the saved input pointer over
the complete saved sequence after invalid UTF-8 input
- CVE-2026-48142
Updated packages:
-
nginx1.25_1.25.5-1~bookworm+tuxcare.els17_amd64.deb
sha:1f3fe95d2da7f3b8e444e8cc854351fb9e853121
-
nginx1.25_1.25.5-1~bookworm+tuxcare.els17_arm64.deb
sha:53b0c5d3f1fa859679317d9e6a7dfc5af41d19f0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.