[CLSA-2026:1785413456] nginx: Fix of CVE-2026-42533
Type:
security
Severity:
Important
Release date:
2026-07-30 12:11:07 UTC
Description:
- CVE-2026-42533: add script-engine buffer overrun protection to fix heap buffer overflow when a map regex capture (or a non-cacheable variable) is used in a string expression
CVEs fixed:
Updated packages:
  • nginx-1.20.1-10.el7.tuxcare.els6.x86_64.rpm
    sha:3844d15855315646c34c12776b993175f1243f1bc33d4693e5cd4769d9d141a3
  • nginx-all-modules-1.20.1-10.el7.tuxcare.els6.noarch.rpm
    sha:b6564905c035dd2d9f328e8e8323d0569bfe96bc973f3403fd9584ab9e94634f
  • nginx-filesystem-1.20.1-10.el7.tuxcare.els6.noarch.rpm
    sha:e6704afb62451bb9534d252b043fa55b0bbea93c2c4a89ae10a8d4d9ad496f7e
  • nginx-mod-devel-1.20.1-10.el7.tuxcare.els6.x86_64.rpm
    sha:bda0e68c8d8407e9660620d403988c03107869ca142dd106c9f8bde26df40f87
  • nginx-mod-http-image-filter-1.20.1-10.el7.tuxcare.els6.x86_64.rpm
    sha:35c6c92890db29934daf188a9aea1400261f315e1f6e76ea72a506caeadb1eff
  • nginx-mod-http-perl-1.20.1-10.el7.tuxcare.els6.x86_64.rpm
    sha:5a301925ae539a473e8e7452af906431d201e5c63cc68a8f15d835e4f23f074c
  • nginx-mod-http-xslt-filter-1.20.1-10.el7.tuxcare.els6.x86_64.rpm
    sha:994351a8e9b330a47926caa6f5fe9552896440e28fd7c628ea33285a25efbb8a
  • nginx-mod-mail-1.20.1-10.el7.tuxcare.els6.x86_64.rpm
    sha:d1b33438d6b3e8dcae574b4ff9579fcd732058de2078167a37b54ac99a4b4f53
  • nginx-mod-stream-1.20.1-10.el7.tuxcare.els6.x86_64.rpm
    sha:4010442f3d966e4cfd0d04723a74ec7e82154addc40c424785c061898e0f5eb2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.