[CLSA-2026:1787916225] nginx: Fix of CVE-2026-56434
Type:
security
Severity:
Important
Release date:
2026-08-28 11:23:56 UTC
Description:
- CVE-2026-56434: fix use-after-free in ngx_http_ssi_filter_module from duplicate subrequest finalization; ngx_http_post_request() now skips posting a request that is already queued, and ngx_http_finalize_request() resets r->write_event_handler to a no-op handler during active subrequest finalization
CVEs fixed:
Updated packages:
  • nginx-1.20.1-14.el9_2.1.alma.1.tuxcare.els14.x86_64.rpm
    sha:cff24776b340b28a5ee7c24218ddcfb36d3511299ce66d6b1fb7149e670b41c9
  • nginx-all-modules-1.20.1-14.el9_2.1.alma.1.tuxcare.els14.noarch.rpm
    sha:de540c684402824a89201831e2c231ab0ef25db21e3fe2e5e116b5a480f23e46
  • nginx-core-1.20.1-14.el9_2.1.alma.1.tuxcare.els14.x86_64.rpm
    sha:cd4a73a2c8fa1c2b76c46b56d1fd235dba8b863a488cb77dee71a4f0e27e55f3
  • nginx-filesystem-1.20.1-14.el9_2.1.alma.1.tuxcare.els14.noarch.rpm
    sha:8ea0300bed72d390954f473e9d2a305b6faf2e304a1a447c23864be040a6a5b2
  • nginx-mod-devel-1.20.1-14.el9_2.1.alma.1.tuxcare.els14.x86_64.rpm
    sha:5984450a2857695a0a2581003dd3eb70cd458beb7521481151338936b74ef87e
  • nginx-mod-http-image-filter-1.20.1-14.el9_2.1.alma.1.tuxcare.els14.x86_64.rpm
    sha:1d876a41d331e8c31ee7f3a6359a1695cfea942bca43d5e0d752636cab2e9a7a
  • nginx-mod-http-perl-1.20.1-14.el9_2.1.alma.1.tuxcare.els14.x86_64.rpm
    sha:fc65b4b922edcfdc260f4a6508344da35da4b8f70a97e2243c666143f0949860
  • nginx-mod-http-xslt-filter-1.20.1-14.el9_2.1.alma.1.tuxcare.els14.x86_64.rpm
    sha:b6f80c72b972f7716e3df7551e93ff427f4836b2dd6f6a3ff5d35c96d1c2ae87
  • nginx-mod-mail-1.20.1-14.el9_2.1.alma.1.tuxcare.els14.x86_64.rpm
    sha:b95ca5f6ea0c11bfeb65fcb27fb3eb26fdf0520937b1583b6e966b53a0f1b367
  • nginx-mod-stream-1.20.1-14.el9_2.1.alma.1.tuxcare.els14.x86_64.rpm
    sha:b3d6480fd5beba21bfa84dce9601f96250fc4d1e3afcffc0422a7c679096b6cb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.