[CLSA-2026:1786709580] Fix of 14 CVEs
Type:
security
Severity:
Critical
Release date:
2026-08-17 16:02:42 UTC
Description:
* SECURITY UPDATE: Heap buffer overflow in njs proxy URL credential decoding - debian/patches/CVE-2026-8711.patch: size decoded username and password buffers from their encoded input lengths and add a regression test - CVE-2026-8711 * SECURITY UPDATE: Use-after-free caused by duplicate subrequest finalization - debian/patches/CVE-2026-56434.patch: prevent duplicate request posting and reset the write event handler during active subrequest finalization - CVE-2026-56434 * SECURITY UPDATE: Heap buffer overflow from oversized gRPC headers - debian/patches/CVE-2026-42055.patch: enforce HTTP/2 field length limits when constructing gRPC requests - CVE-2026-42055 * SECURITY UPDATE: Buffer over-read while recoding invalid UTF-8 sequences - debian/patches/CVE-2026-48142.patch: advance the saved input pointer over the complete saved sequence after invalid UTF-8 input - CVE-2026-48142
Updated packages:
  • nginx1.25_1.25.5-1~bookworm+tuxcare.els17_amd64.deb
    sha:1f3fe95d2da7f3b8e444e8cc854351fb9e853121
  • nginx1.25_1.25.5-1~bookworm+tuxcare.els17_arm64.deb
    sha:53b0c5d3f1fa859679317d9e6a7dfc5af41d19f0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.