[CLSA-2026:1790928452] nginx: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2026-10-02 17:04:16 UTC
Description:
- CVE-2026-27651: fix null pointer dereference in ngx_mail_auth_http_module when clearing the password in auth http requests with CRAM-MD5/APOP - CVE-2026-27654: fix heap buffer overflow in ngx_http_dav_module when a COPY/MOVE destination URI is shorter than the location alias - CVE-2026-27654: also require the COPY/MOVE Destination to match the aliased location prefix, and tighten ngx_http_map_uri_to_path() accordingly - CVE-2026-27784: fix integer overflow in ngx_http_mp4_module atom entry count validation on 32-bit platforms
Updated packages:
  • nginx-1.20.1-10.el7.tuxcare.els9.i686.rpm
    sha:304246cf59d6579e69cd2b55d72c11de7f1e5eb072899db4a501b89f9f6dea7a
  • nginx-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
    sha:b37dfdef0bdf2db508bb226057d4657e97381d240d599435460750c517c4fcae
  • nginx-all-modules-1.20.1-10.el7.tuxcare.els9.noarch.rpm
    sha:31a745636997423be01685d402a7ffaa2cf475b56c81c8e5b66735a18fe2d36e
  • nginx-filesystem-1.20.1-10.el7.tuxcare.els9.noarch.rpm
    sha:0d040c134169f1766f8d1484393dcd5ca58079b861e9aae638b85f7bb31217e9
  • nginx-mod-devel-1.20.1-10.el7.tuxcare.els9.i686.rpm
    sha:b0bdd65c8f1fc94c2ae8a704cd00a37d2f4678dcad7086a243d6a04db5c9d0f8
  • nginx-mod-devel-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
    sha:71301137bb9a15f3f323d8d200e369dd67f441ffa4b20b8e413117d60a6e4601
  • nginx-mod-http-image-filter-1.20.1-10.el7.tuxcare.els9.i686.rpm
    sha:6e57350ed839a49820fd8edbcd57dd22bb9f567b456d1ab9eab94b28a6dd4257
  • nginx-mod-http-image-filter-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
    sha:4a767dc92d11dd1adf50b0dfa15700652eec6d645efdd818b2ff269538b4396c
  • nginx-mod-http-perl-1.20.1-10.el7.tuxcare.els9.i686.rpm
    sha:d0bd2cc6c77c432a541dff614ca2292d6b49cbd7c11748b823d01d55adb13ea3
  • nginx-mod-http-perl-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
    sha:bf0f6538a7fd73415a7213d22e1b8d999bdb846aff99caf08f269564c39bb83b
  • nginx-mod-http-xslt-filter-1.20.1-10.el7.tuxcare.els9.i686.rpm
    sha:c37dcec1905206461b3f28ae7d8d56c4152995c891a4b3e21a63418891699ad4
  • nginx-mod-http-xslt-filter-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
    sha:05f3ab140530677f70be9f9c182b979bd74194ceb6d2ea14fd6e07fc2e668976
  • nginx-mod-mail-1.20.1-10.el7.tuxcare.els9.i686.rpm
    sha:f8a7c5a933a6fcde3338fa6f66ab311654efa60843900e70c483b504707022b1
  • nginx-mod-mail-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
    sha:8c0b94fb80b85622ebfd05d3d0bff38c1ab767817e0712a482e09a68104c8e1a
  • nginx-mod-stream-1.20.1-10.el7.tuxcare.els9.i686.rpm
    sha:d3d7d01d62e7c8d83875588a3f08c60900e5116bc266cb9b20712bd67e707aae
  • nginx-mod-stream-1.20.1-10.el7.tuxcare.els9.x86_64.rpm
    sha:933b0eb6f4e6785c56140638c71075aa77348d21040d74c9699df9bae473a9d5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.