[CLSA-2026:1780912663] Fix of 6 CVEs
Type:
security
Severity:
Important
Release date:
2026-06-08 09:58:07 UTC
Description:
* SECURITY UPDATE: detect premature plain text response from SSL upstream (TLS plaintext injection) - debian/patches/CVE-2026-1642.patch: detect premature plain text response from SSL upstream (TLS plaintext injection) - CVE-2026-1642 * SECURITY UPDATE: fix NULL pointer dereference clearing s->passwd in mail auth http requests - debian/patches/CVE-2026-27651.patch: fix NULL pointer dereference clearing s->passwd in mail auth http requests - CVE-2026-27651 * SECURITY UPDATE: destination length validation for WebDAV COPY and MOVE (heap buffer overflow) - debian/patches/CVE-2026-27654.patch: destination length validation for WebDAV COPY and MOVE (heap buffer overflow) - CVE-2026-27654 * SECURITY UPDATE: fix integer overflow on 32-bit platforms in ngx_http_mp4_module - debian/patches/CVE-2026-27784.patch: fix integer overflow on 32-bit platforms in ngx_http_mp4_module - CVE-2026-27784 * SECURITY UPDATE: avoid zero size buffers in ngx_http_mp4_module output (out-of-bounds access) - debian/patches/CVE-2026-32647.patch: avoid zero size buffers in ngx_http_mp4_module output (out-of-bounds access) - CVE-2026-32647 * SECURITY UPDATE: reject unsafe characters in URIs and headers set via the Lua API (HTTP response splitting) - debian/modules/nginx-lua/src/ngx_http_lua_util.c, debian/modules/nginx-lua/src/ngx_http_lua_util.h, debian/modules/nginx-lua/src/ngx_http_lua_uri.c, debian/modules/nginx-lua/src/ngx_http_lua_headers_in.c, debian/modules/nginx-lua/src/ngx_http_lua_headers_out.c, debian/modules/nginx-lua/src/ngx_http_lua_control.c: validate arguments of the Lua APIs that mutate a URI or a request/response header so control characters raise an error instead of being silently truncated. - CVE-2020-36309
Updated packages:
  • nginx_1.10.3-0ubuntu0.16.04.8+tuxcare.els8_all.deb
    sha:d868c7b1bc5b19208cb9a3d9ab9e9f4cce8a0e21
  • nginx-common_1.10.3-0ubuntu0.16.04.8+tuxcare.els8_all.deb
    sha:9f871bb313b18d71c73b421d6cebcce0910de8cc
  • nginx-core_1.10.3-0ubuntu0.16.04.8+tuxcare.els8_amd64.deb
    sha:eeec4bb35aec97aa5c2da80da089b2bc6970294f
  • nginx-doc_1.10.3-0ubuntu0.16.04.8+tuxcare.els8_all.deb
    sha:624da1af6cc23e9a344cb956a20d188b56a648d0
  • nginx-extras_1.10.3-0ubuntu0.16.04.8+tuxcare.els8_amd64.deb
    sha:5f27b98aeb895b66e49a5b622ed39b240912f6e4
  • nginx-full_1.10.3-0ubuntu0.16.04.8+tuxcare.els8_amd64.deb
    sha:f673d07fee525b9610c655bad1f8c31cb01814a9
  • nginx-light_1.10.3-0ubuntu0.16.04.8+tuxcare.els8_amd64.deb
    sha:7657bcb993a27eaea4f1aba6ebaec0abbde877e7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.