[CLSA-2026:1779126256] Fix CVE(s): CVE-2026-42945
Type:
security
Severity:
Important
Release date:
2026-05-18 17:44:20 UTC
Description:
* SECURITY UPDATE: fix heap buffer overrun in ngx_http_rewrite_module when rewrite is followed by set/if/rewrite with unnamed PCRE captures - debian/patches/CVE-2026-42945.patch: fix heap buffer overrun in ngx_http_rewrite_module when rewrite is followed by set/if/rewrite with unnamed PCRE captures - CVE-2026-42945
Updated packages:
  • nginx_1.10.3-0ubuntu0.16.04.8+tuxcare.els6_all.deb
    sha:16597fec159f786f91d4ab994101044598ecc565
  • nginx-common_1.10.3-0ubuntu0.16.04.8+tuxcare.els6_all.deb
    sha:fa16693af51a274ef176a38efc73c1b673ca5825
  • nginx-core_1.10.3-0ubuntu0.16.04.8+tuxcare.els6_amd64.deb
    sha:456465f00e6bbc7b71dc5422ed60c0c9bb4550f0
  • nginx-doc_1.10.3-0ubuntu0.16.04.8+tuxcare.els6_all.deb
    sha:8c78d836e3d08a0984f3e2e7232430f946e3b455
  • nginx-extras_1.10.3-0ubuntu0.16.04.8+tuxcare.els6_amd64.deb
    sha:58759c1d02ace925d91fd60a603049e6e7e28dad
  • nginx-full_1.10.3-0ubuntu0.16.04.8+tuxcare.els6_amd64.deb
    sha:bc8dcad005903eb3449834b662e42797e157aeb7
  • nginx-light_1.10.3-0ubuntu0.16.04.8+tuxcare.els6_amd64.deb
    sha:cca51a1ec40b794faf9710cc65149aa58b5f905f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.