Release date:
2026-09-14 12:49:12 UTC
Description:
* SECURITY UPDATE: buffer over-read in the mp4 module while cropping the stsc
atom of a specially crafted mp4 file, which could terminate the worker
process
- debian/patches/CVE-2024-7347.patch: widen n to uint64_t and cast the
(next_chunk - chunk) * samples multiplications in
ngx_http_mp4_crop_stsc_data() to avoid a 32-bit integer overflow,
reject stsc atoms whose chunks are unordered, and ignore the samples
per chunk value of an empty chunk run
- CVE-2024-7347
* SECURITY UPDATE: client certificate verification bypass through TLSv1.3
session resumption with a server name other than the negotiated one
- debian/patches/CVE-2025-23419.patch: reject a resumed handshake in
ngx_http_ssl_servername() when the session host name differs from the
requested server name and the virtual server verifies client
certificates
- CVE-2025-23419
Updated packages:
-
nginx1.23_1.23.4-1~trixie+tuxcare.els15_amd64.deb
sha:235301e796ae94ad5f901dd247a0b07fa212c03e
-
nginx1.23_1.23.4-1~trixie+tuxcare.els15_arm64.deb
sha:72100c953b2021efb3a64d638d69d821046360da
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.