[CLSA-2026:1789388125] Fix CVE(s): CVE-2024-7347, CVE-2025-23419
Type:
security
Severity:
Moderate
Release date:
2026-09-14 12:15:48 UTC
Description:
* SECURITY UPDATE: buffer over-read in the mp4 module while cropping the stsc atom of a specially crafted mp4 file, which could terminate the worker process - debian/patches/CVE-2024-7347.patch: widen n to uint64_t and cast the (next_chunk - chunk) * samples multiplications in ngx_http_mp4_crop_stsc_data() to avoid a 32-bit integer overflow, reject stsc atoms whose chunks are unordered, and ignore the samples per chunk value of an empty chunk run - CVE-2024-7347 * SECURITY UPDATE: client certificate verification bypass through TLSv1.3 session resumption with a server name other than the negotiated one - debian/patches/CVE-2025-23419.patch: reject a resumed handshake in ngx_http_ssl_servername() when the session host name differs from the requested server name and the virtual server verifies client certificates - CVE-2025-23419
Updated packages:
  • nginx1.23_1.23.4-1~bookworm+tuxcare.els15_amd64.deb
    sha:c815e3ddde668a732a07bfa064a077660acb040f
  • nginx1.23_1.23.4-1~bookworm+tuxcare.els15_arm64.deb
    sha:f9d2abca05c140ea5820708a0a40545e79f74fc3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.