[CLSA-2026:1781255826] Fix of 6 CVEs
Type:
security
Severity:
Important
Release date:
2026-06-12 09:17:34 UTC
Description:
* SECURITY UPDATE: response injection from SSL upstream when a MITM-positioned backend delivers a plain text response before the TLS handshake completes - debian/patches/CVE-2026-1642.patch: reject plain text reads in ngx_http_upstream_process_header when u->ssl is set but c->ssl is NULL - CVE-2026-1642 * SECURITY UPDATE: memory disclosure and worker crash in ngx_http_scgi_module and ngx_http_uwsgi_module when scgi_pass or uwsgi_pass is configured and a MITM-positioned upstream returns an invalid status line, due to header parsing resuming with a stale r->state after the status-line fallback - debian/patches/CVE-2026-42946.patch: reset r->state to 0 in the NGX_ERROR fallback branch of ngx_http_scgi_process_status_line and ngx_http_uwsgi_process_status_line before delegating to the generic header parser - CVE-2026-42946
Updated packages:
  • nginx1.21_1.21.6-1~bookworm+tuxcare.els9_amd64.deb
    sha:3501b64b36e4dea18240bcd516629c90d2fe2911
  • nginx1.21_1.21.6-1~bookworm+tuxcare.els9_arm64.deb
    sha:951104e68655adc59fc71d63d0f41ce3cf8fafe3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.