[CLSA-2026:1789135842] Fix CVE(s): CVE-2025-23419, CVE-2026-42934
Type:
security
Severity:
Moderate
Release date:
2026-09-11 14:10:53 UTC
Description:
* SECURITY UPDATE: Client certificate authentication bypass through TLSv1.3 cross-SNI session resumption - debian/patches/CVE-2025-23419.patch: reject a resumed TLSv1.3 session whose SNI server name differs from the one negotiated when the session was created, in both the HTTP and the stream SSL paths - CVE-2025-23419 * SECURITY UPDATE: Buffer over-read in the charset filter while saving an incomplete UTF-8 sequence - debian/patches/CVE-2026-42934.patch: bound the saved UTF-8 sequence copy by the number of bytes actually left in the input buffer - CVE-2026-42934 * SECURITY UPDATE: Worker process crash from HTTP/3 decoder stream creation during connection shutdown - debian/patches/CVE-2024-31079.patch: pre-create the decoder stream while sending HTTP/3 settings and skip creating it later once the stream is already gone - CVE-2024-31079
Updated packages:
  • nginx1.25_1.25.5-1~bookworm+tuxcare.els18_amd64.deb
    sha:baed6426ce0b0734d90c913167051b7089378ea7
  • nginx1.25_1.25.5-1~bookworm+tuxcare.els18_arm64.deb
    sha:e6357585a442ea04d7d294023e0ae4b5dc20e28f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.