[CLSA-2026:1786964556] Fix CVE(s): CVE-2026-42055, CVE-2026-56434
Type:
security
Severity:
Critical
Release date:
2026-08-17 11:02:47 UTC
Description:
* SECURITY UPDATE: heap buffer overflow when proxying oversized headers to an HTTP/2 or gRPC upstream, and when emitting oversized Content-Type and Location response headers over HTTP/2 - debian/patches/CVE-2026-42055.patch: reject header fields longer than NGX_HTTP_V2_MAX_FIELD in ngx_http_grpc_create_request() for the method name, uri, host and each header key and value, and add the same length guards for content_type and location in ngx_http_v2_header_filter() - CVE-2026-42055 * SECURITY UPDATE: use-after-free in the ssi module during unbuffered proxying when a subrequest was posted twice and finalized in both calls - debian/patches/CVE-2026-56434.patch: skip posting a request that is already on r->main->posted_requests, and reset r->write_event_handler to ngx_http_request_empty_handler during subrequest finalization - CVE-2026-56434
Updated packages:
  • nginx1.23_1.23.4-1~bookworm+tuxcare.els14_amd64.deb
    sha:ee522b1f79f8bd6d700bdee9130cd6d826d136b7
  • nginx1.23_1.23.4-1~bookworm+tuxcare.els14_arm64.deb
    sha:f132f615646567b1f8b77bda7639a4db3e45b539
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.