[CLSA-2026:1785328094] nginx: Fix of CVE-2026-48142
Type:
security
Severity:
Moderate
Release date:
2026-07-29 12:28:25 UTC
Description:
- CVE-2026-48142: heap out-of-bounds read in ngx_http_charset_recode_from_utf8() when an invalid UTF-8 sequence split across buffers rewinds src before the buffer start, on locations recoding source_charset utf-8 to another charset
CVEs fixed:
Updated packages:
  • nginx-1.14.1-9.module_el8+2455+58360e39.tuxcare.els13.x86_64.rpm
    sha:959ce3b57f6942e1c955ded15c988f4c2b1a9ef9fad3f630efcabc4ad962eb87
  • nginx-all-modules-1.14.1-9.module_el8+2455+58360e39.tuxcare.els13.noarch.rpm
    sha:27c21a9c98e45a765dbda7a315463d031a77f83a741ca5b6f62d006602ad9172
  • nginx-filesystem-1.14.1-9.module_el8+2455+58360e39.tuxcare.els13.noarch.rpm
    sha:d33302b7194594953751fec31ca08f4206cb0618d7598177699f058b29101b02
  • nginx-mod-http-image-filter-1.14.1-9.module_el8+2455+58360e39.tuxcare.els13.x86_64.rpm
    sha:06955f8990d4da4dcd6e52f9cf8126818684a37b975785631b8eefb22476b403
  • nginx-mod-http-perl-1.14.1-9.module_el8+2455+58360e39.tuxcare.els13.x86_64.rpm
    sha:605a70584234c4a160518c9334bc5f6c8cb15627171387ebfc769dd6a1c5b79b
  • nginx-mod-http-xslt-filter-1.14.1-9.module_el8+2455+58360e39.tuxcare.els13.x86_64.rpm
    sha:37d40abc604bbd636330d6d50088b83b4f0d20b43b689f546ffc1ef51fc9eb6a
  • nginx-mod-mail-1.14.1-9.module_el8+2455+58360e39.tuxcare.els13.x86_64.rpm
    sha:8873c28598b8678615660ff9efcb87719c15599f6d0f47ad4a8143d092ff9eca
  • nginx-mod-stream-1.14.1-9.module_el8+2455+58360e39.tuxcare.els13.x86_64.rpm
    sha:9be856c80f77b0f67dabce33550bde78b43496dcc05c6c1c716e02f6d63d6846
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.