[CLSA-2026:1781257912] Fix of 6 CVEs
Type:
security
Severity:
Important
Release date:
2026-06-12 09:52:16 UTC
Description:
* SECURITY UPDATE: response injection from SSL upstream when a MITM-positioned backend delivers a plain text response before the TLS handshake completes - debian/patches/CVE-2026-1642.patch: reject plain text reads in ngx_http_upstream_process_header when u->ssl is set but c->ssl is NULL - CVE-2026-1642 * SECURITY UPDATE: memory disclosure and worker crash in ngx_http_scgi_module and ngx_http_uwsgi_module when scgi_pass or uwsgi_pass is configured and a MITM-positioned upstream returns an invalid status line, due to header parsing resuming with a stale r->state after the status-line fallback - debian/patches/CVE-2026-42946.patch: reset r->state to 0 in the NGX_ERROR fallback branch of ngx_http_scgi_process_status_line and ngx_http_uwsgi_process_status_line before delegating to the generic header parser - CVE-2026-42946
Updated packages:
  • nginx1.21_1.21.6-1~trixie+tuxcare.els9_amd64.deb
    sha:b24ba1d412b4da18e04f9bda013d7883d9267454
  • nginx1.21_1.21.6-1~trixie+tuxcare.els9_arm64.deb
    sha:62deb3e3f52230603269b683b88923a949ee6806
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.