[CLSA-2026:1779892646] nginx: Fix of CVE-2026-42945
Type:
security
Severity:
Important
Release date:
2026-05-27 14:37:31 UTC
Description:
- CVE-2026-42945: fix heap buffer overrun in ngx_http_rewrite_module when rewrite is followed by set/if/rewrite with unnamed PCRE captures
Updated packages:
  • nginx-1.14.1-9.module_el8.4.0+2411+f4af5a37.tuxcare.els8.x86_64.rpm
    sha:afc1213e9d5cde47cfdb65fb541bfe589db99b7205d1097028de0aa240989ef3
  • nginx-all-modules-1.14.1-9.module_el8.4.0+2411+f4af5a37.tuxcare.els8.noarch.rpm
    sha:eb2d4a848931be2a9dfeec99959c733c50c42e1ed757435ca9bf216bda6e69a1
  • nginx-filesystem-1.14.1-9.module_el8.4.0+2411+f4af5a37.tuxcare.els8.noarch.rpm
    sha:2c35aecb332176fd14f3a59b134522f0b32b42f5b5aa58d24d13d2459679849a
  • nginx-mod-http-image-filter-1.14.1-9.module_el8.4.0+2411+f4af5a37.tuxcare.els8.x86_64.rpm
    sha:452e59ce2dbdc2384c3c8bf4902116e5e51b80709d81ddb7c8e5ae614c31d0d5
  • nginx-mod-http-perl-1.14.1-9.module_el8.4.0+2411+f4af5a37.tuxcare.els8.x86_64.rpm
    sha:0901a0b9bc3142b0af03da13adbb2ff257eeef87b56fc0a89915baac253a07be
  • nginx-mod-http-xslt-filter-1.14.1-9.module_el8.4.0+2411+f4af5a37.tuxcare.els8.x86_64.rpm
    sha:8f1ad9f1ac0d993aa61ec0475b695a5d2e6483bda8cff2a3d97a1615455d95ac
  • nginx-mod-mail-1.14.1-9.module_el8.4.0+2411+f4af5a37.tuxcare.els8.x86_64.rpm
    sha:be818ae0bd032517b910ac084ee684cd389a9717fd6d35130194f270bb9f5160
  • nginx-mod-stream-1.14.1-9.module_el8.4.0+2411+f4af5a37.tuxcare.els8.x86_64.rpm
    sha:c74bbe3985723a7243d6bc0086a20ebf8a883c268625aadca3634e33455cf70c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.