Release date:
2026-08-17 16:11:27 UTC
Description:
* SECURITY UPDATE: Heap buffer overflow in njs proxy URL credential decoding
- debian/patches/CVE-2026-8711.patch: size decoded username and password
buffers from their encoded input lengths and add a regression test
- CVE-2026-8711
* SECURITY UPDATE: Use-after-free caused by duplicate subrequest finalization
- debian/patches/CVE-2026-56434.patch: prevent duplicate request posting and
reset the write event handler during active subrequest finalization
- CVE-2026-56434
* SECURITY UPDATE: Heap buffer overflow from oversized gRPC headers
- debian/patches/CVE-2026-42055.patch: enforce HTTP/2 field length limits
when constructing gRPC requests
- CVE-2026-42055
* SECURITY UPDATE: Buffer over-read while recoding invalid UTF-8 sequences
- debian/patches/CVE-2026-48142.patch: advance the saved input pointer over
the complete saved sequence after invalid UTF-8 input
- CVE-2026-48142
Updated packages:
-
nginx1.25_1.25.5-1~trixie+tuxcare.els17_amd64.deb
sha:3894bb22c50d8e2f5e0532914aa381ddaf924b6a
-
nginx1.25_1.25.5-1~trixie+tuxcare.els17_arm64.deb
sha:3c674b117947a278595ece694f9dd74ed20af6cc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.