Release date:
2026-09-11 14:20:42 UTC
Description:
* SECURITY UPDATE: Client certificate authentication bypass through TLSv1.3
cross-SNI session resumption
- debian/patches/CVE-2025-23419.patch: reject a resumed TLSv1.3 session
whose SNI server name differs from the one negotiated when the session
was created, in both the HTTP and the stream SSL paths
- CVE-2025-23419
* SECURITY UPDATE: Buffer over-read in the charset filter while saving an
incomplete UTF-8 sequence
- debian/patches/CVE-2026-42934.patch: bound the saved UTF-8 sequence copy
by the number of bytes actually left in the input buffer
- CVE-2026-42934
* SECURITY UPDATE: Worker process crash from HTTP/3 decoder stream creation
during connection shutdown
- debian/patches/CVE-2024-31079.patch: pre-create the decoder stream while
sending HTTP/3 settings and skip creating it later once the stream is
already gone
- CVE-2024-31079
Updated packages:
-
nginx1.25_1.25.5-1~trixie+tuxcare.els18_amd64.deb
sha:b16fbf17f9bc4d3ece737c186afca8a5e85d416b
-
nginx1.25_1.25.5-1~trixie+tuxcare.els18_arm64.deb
sha:0073340a1379a9356827f2eaff961c4f9566dc45
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.