[CLSA-2026:1786965098] Fix CVE(s): CVE-2026-42055, CVE-2026-56434
Type:
security
Severity:
Critical
Release date:
2026-08-17 11:11:50 UTC
Description:
* SECURITY UPDATE: heap buffer overflow when proxying oversized headers to an HTTP/2 or gRPC upstream, and when emitting oversized Content-Type and Location response headers over HTTP/2 - debian/patches/CVE-2026-42055.patch: reject header fields longer than NGX_HTTP_V2_MAX_FIELD in ngx_http_grpc_create_request() for the method name, uri, host and each header key and value, and add the same length guards for content_type and location in ngx_http_v2_header_filter() - CVE-2026-42055 * SECURITY UPDATE: use-after-free in the ssi module during unbuffered proxying when a subrequest was posted twice and finalized in both calls - debian/patches/CVE-2026-56434.patch: skip posting a request that is already on r->main->posted_requests, and reset r->write_event_handler to ngx_http_request_empty_handler during subrequest finalization - CVE-2026-56434
Updated packages:
  • nginx1.23_1.23.4-1~trixie+tuxcare.els14_amd64.deb
    sha:e7245e4709a49a389237c5ef1210aed09974fd31
  • nginx1.23_1.23.4-1~trixie+tuxcare.els14_arm64.deb
    sha:6d1c7662d4ba8afd9446bbf68efeb619aafdb8bb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.