[CLSA-2026:1789390129] Fix CVE(s): CVE-2024-7347, CVE-2025-23419
Type:
security
Severity:
Moderate
Release date:
2026-09-14 12:49:12 UTC
Description:
* SECURITY UPDATE: buffer over-read in the mp4 module while cropping the stsc atom of a specially crafted mp4 file, which could terminate the worker process - debian/patches/CVE-2024-7347.patch: widen n to uint64_t and cast the (next_chunk - chunk) * samples multiplications in ngx_http_mp4_crop_stsc_data() to avoid a 32-bit integer overflow, reject stsc atoms whose chunks are unordered, and ignore the samples per chunk value of an empty chunk run - CVE-2024-7347 * SECURITY UPDATE: client certificate verification bypass through TLSv1.3 session resumption with a server name other than the negotiated one - debian/patches/CVE-2025-23419.patch: reject a resumed handshake in ngx_http_ssl_servername() when the session host name differs from the requested server name and the virtual server verifies client certificates - CVE-2025-23419
Updated packages:
  • nginx1.23_1.23.4-1~trixie+tuxcare.els15_amd64.deb
    sha:235301e796ae94ad5f901dd247a0b07fa212c03e
  • nginx1.23_1.23.4-1~trixie+tuxcare.els15_arm64.deb
    sha:72100c953b2021efb3a64d638d69d821046360da
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.