Release date:
2026-08-17 11:02:47 UTC
Description:
* SECURITY UPDATE: heap buffer overflow when proxying oversized headers to
an HTTP/2 or gRPC upstream, and when emitting oversized Content-Type and
Location response headers over HTTP/2
- debian/patches/CVE-2026-42055.patch: reject header fields longer than
NGX_HTTP_V2_MAX_FIELD in ngx_http_grpc_create_request() for the method
name, uri, host and each header key and value, and add the same length
guards for content_type and location in ngx_http_v2_header_filter()
- CVE-2026-42055
* SECURITY UPDATE: use-after-free in the ssi module during unbuffered
proxying when a subrequest was posted twice and finalized in both calls
- debian/patches/CVE-2026-56434.patch: skip posting a request that is
already on r->main->posted_requests, and reset r->write_event_handler
to ngx_http_request_empty_handler during subrequest finalization
- CVE-2026-56434
Updated packages:
-
nginx1.23_1.23.4-1~bookworm+tuxcare.els14_amd64.deb
sha:ee522b1f79f8bd6d700bdee9130cd6d826d136b7
-
nginx1.23_1.23.4-1~bookworm+tuxcare.els14_arm64.deb
sha:f132f615646567b1f8b77bda7639a4db3e45b539
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.