Release date:
2026-06-12 09:17:34 UTC
Description:
* SECURITY UPDATE: response injection from SSL upstream when a MITM-positioned
backend delivers a plain text response before the TLS handshake completes
- debian/patches/CVE-2026-1642.patch: reject plain text reads in
ngx_http_upstream_process_header when u->ssl is set but c->ssl is NULL
- CVE-2026-1642
* SECURITY UPDATE: memory disclosure and worker crash in
ngx_http_scgi_module and ngx_http_uwsgi_module when scgi_pass or
uwsgi_pass is configured and a MITM-positioned upstream returns an
invalid status line, due to header parsing resuming with a stale
r->state after the status-line fallback
- debian/patches/CVE-2026-42946.patch: reset r->state to 0 in the
NGX_ERROR fallback branch of ngx_http_scgi_process_status_line and
ngx_http_uwsgi_process_status_line before delegating to the
generic header parser
- CVE-2026-42946
Updated packages:
-
nginx1.21_1.21.6-1~bookworm+tuxcare.els9_amd64.deb
sha:3501b64b36e4dea18240bcd516629c90d2fe2911
-
nginx1.21_1.21.6-1~bookworm+tuxcare.els9_arm64.deb
sha:951104e68655adc59fc71d63d0f41ce3cf8fafe3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.