Release date:
2026-06-08 09:58:07 UTC
Description:
* SECURITY UPDATE: detect premature plain text response from SSL upstream (TLS plaintext injection)
- debian/patches/CVE-2026-1642.patch: detect premature plain text response from SSL upstream (TLS plaintext injection)
- CVE-2026-1642
* SECURITY UPDATE: fix NULL pointer dereference clearing s->passwd in mail auth http requests
- debian/patches/CVE-2026-27651.patch: fix NULL pointer dereference clearing s->passwd in mail auth http requests
- CVE-2026-27651
* SECURITY UPDATE: destination length validation for WebDAV COPY and MOVE (heap buffer overflow)
- debian/patches/CVE-2026-27654.patch: destination length validation for WebDAV COPY and MOVE (heap buffer overflow)
- CVE-2026-27654
* SECURITY UPDATE: fix integer overflow on 32-bit platforms in ngx_http_mp4_module
- debian/patches/CVE-2026-27784.patch: fix integer overflow on 32-bit platforms in ngx_http_mp4_module
- CVE-2026-27784
* SECURITY UPDATE: avoid zero size buffers in ngx_http_mp4_module output (out-of-bounds access)
- debian/patches/CVE-2026-32647.patch: avoid zero size buffers in ngx_http_mp4_module output (out-of-bounds access)
- CVE-2026-32647
* SECURITY UPDATE: reject unsafe characters in URIs and headers set via the Lua API (HTTP response splitting)
- debian/modules/nginx-lua/src/ngx_http_lua_util.c,
debian/modules/nginx-lua/src/ngx_http_lua_util.h,
debian/modules/nginx-lua/src/ngx_http_lua_uri.c,
debian/modules/nginx-lua/src/ngx_http_lua_headers_in.c,
debian/modules/nginx-lua/src/ngx_http_lua_headers_out.c,
debian/modules/nginx-lua/src/ngx_http_lua_control.c: validate
arguments of the Lua APIs that mutate a URI or a request/response
header so control characters raise an error instead of being
silently truncated.
- CVE-2020-36309
Updated packages:
-
nginx_1.10.3-0ubuntu0.16.04.8+tuxcare.els8_all.deb
sha:d868c7b1bc5b19208cb9a3d9ab9e9f4cce8a0e21
-
nginx-common_1.10.3-0ubuntu0.16.04.8+tuxcare.els8_all.deb
sha:9f871bb313b18d71c73b421d6cebcce0910de8cc
-
nginx-core_1.10.3-0ubuntu0.16.04.8+tuxcare.els8_amd64.deb
sha:eeec4bb35aec97aa5c2da80da089b2bc6970294f
-
nginx-doc_1.10.3-0ubuntu0.16.04.8+tuxcare.els8_all.deb
sha:624da1af6cc23e9a344cb956a20d188b56a648d0
-
nginx-extras_1.10.3-0ubuntu0.16.04.8+tuxcare.els8_amd64.deb
sha:5f27b98aeb895b66e49a5b622ed39b240912f6e4
-
nginx-full_1.10.3-0ubuntu0.16.04.8+tuxcare.els8_amd64.deb
sha:f673d07fee525b9610c655bad1f8c31cb01814a9
-
nginx-light_1.10.3-0ubuntu0.16.04.8+tuxcare.els8_amd64.deb
sha:7657bcb993a27eaea4f1aba6ebaec0abbde877e7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.