Release date:
2026-09-11 14:10:53 UTC
Description:
* SECURITY UPDATE: Client certificate authentication bypass through TLSv1.3
cross-SNI session resumption
- debian/patches/CVE-2025-23419.patch: reject a resumed TLSv1.3 session
whose SNI server name differs from the one negotiated when the session
was created, in both the HTTP and the stream SSL paths
- CVE-2025-23419
* SECURITY UPDATE: Buffer over-read in the charset filter while saving an
incomplete UTF-8 sequence
- debian/patches/CVE-2026-42934.patch: bound the saved UTF-8 sequence copy
by the number of bytes actually left in the input buffer
- CVE-2026-42934
* SECURITY UPDATE: Worker process crash from HTTP/3 decoder stream creation
during connection shutdown
- debian/patches/CVE-2024-31079.patch: pre-create the decoder stream while
sending HTTP/3 settings and skip creating it later once the stream is
already gone
- CVE-2024-31079
Updated packages:
-
nginx1.25_1.25.5-1~bookworm+tuxcare.els18_amd64.deb
sha:baed6426ce0b0734d90c913167051b7089378ea7
-
nginx1.25_1.25.5-1~bookworm+tuxcare.els18_arm64.deb
sha:e6357585a442ea04d7d294023e0ae4b5dc20e28f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.