[CLSA-2026:1789136430] Fix CVE(s): CVE-2025-23419, CVE-2026-42934
Type:
security
Severity:
Moderate
Release date:
2026-09-11 14:20:42 UTC
Description:
* SECURITY UPDATE: Client certificate authentication bypass through TLSv1.3 cross-SNI session resumption - debian/patches/CVE-2025-23419.patch: reject a resumed TLSv1.3 session whose SNI server name differs from the one negotiated when the session was created, in both the HTTP and the stream SSL paths - CVE-2025-23419 * SECURITY UPDATE: Buffer over-read in the charset filter while saving an incomplete UTF-8 sequence - debian/patches/CVE-2026-42934.patch: bound the saved UTF-8 sequence copy by the number of bytes actually left in the input buffer - CVE-2026-42934 * SECURITY UPDATE: Worker process crash from HTTP/3 decoder stream creation during connection shutdown - debian/patches/CVE-2024-31079.patch: pre-create the decoder stream while sending HTTP/3 settings and skip creating it later once the stream is already gone - CVE-2024-31079
Updated packages:
  • nginx1.25_1.25.5-1~trixie+tuxcare.els18_amd64.deb
    sha:b16fbf17f9bc4d3ece737c186afca8a5e85d416b
  • nginx1.25_1.25.5-1~trixie+tuxcare.els18_arm64.deb
    sha:0073340a1379a9356827f2eaff961c4f9566dc45
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.