[CLSA-2026:1779893017] nginx: Fix of CVE-2026-42945
Type:
security
Severity:
Important
Release date:
2026-05-27 14:43:42 UTC
Description:
- CVE-2026-42945: fix heap buffer overrun in ngx_http_rewrite_module when rewrite is followed by set/if/rewrite with unnamed PCRE captures
Updated packages:
  • nginx-1.14.1-9.module_el8.5.0+2412+cfc82540.tuxcare.els8.x86_64.rpm
    sha:247efc3436219d12deae2eb9f4fdeb0898e3eb64ce055394d9eee924d2b6a26f
  • nginx-all-modules-1.14.1-9.module_el8.5.0+2412+cfc82540.tuxcare.els8.noarch.rpm
    sha:a6a2c78e6282502e0562b0ba010d0e589b6201a3100610a2ca2f9b404f6e651d
  • nginx-filesystem-1.14.1-9.module_el8.5.0+2412+cfc82540.tuxcare.els8.noarch.rpm
    sha:9c92fdf47b1151fc60e8229b60b2f224ce19facd756cf79127d7a509919c9705
  • nginx-mod-http-image-filter-1.14.1-9.module_el8.5.0+2412+cfc82540.tuxcare.els8.x86_64.rpm
    sha:12cd89265e0501c838edf564ef95e578be90f23e3ab816702b9477a79407a2c3
  • nginx-mod-http-perl-1.14.1-9.module_el8.5.0+2412+cfc82540.tuxcare.els8.x86_64.rpm
    sha:da6683fc28f6a0b1eaec2d64ce22be4a03a8c6610540095b7c71d4ae26697537
  • nginx-mod-http-xslt-filter-1.14.1-9.module_el8.5.0+2412+cfc82540.tuxcare.els8.x86_64.rpm
    sha:c1a0d2ec28d8a51cba94231fbbad31e8281fcb3ecc5ae7f6ad9f2c0110bc9008
  • nginx-mod-mail-1.14.1-9.module_el8.5.0+2412+cfc82540.tuxcare.els8.x86_64.rpm
    sha:d16b079baf58f9643ad193bfcc2496d17c27fd6821323cb9b9bf8c8926b28ffe
  • nginx-mod-stream-1.14.1-9.module_el8.5.0+2412+cfc82540.tuxcare.els8.x86_64.rpm
    sha:fe45bfc572bf5f3d9c778513728f31d45fce0fab2e53022c9e632f8fb67fcdb0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.