CLSA-2026-1777022242

See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1777022242.json
JSON Data
https://api.osv.dev/v1/vulns/CLSA-2026-1777022242
Upstream
  • CVE-2026-27651
  • CVE-2026-32647
Published
2026-04-24T09:17:28Z
Modified
2026-06-01T00:32:27.818555692Z
Summary
nginx: Fix of 2 CVEs
Details
  • CVE-2026-32647: fix buffer over-read/over-write in ngxhttpmp4_module via integer overflow, off-by-one boundary checks, and zero sync sample validation in stss atom
  • CVE-2026-27651: fix NULL pointer dereference in ngxmailauthhttpmodule when using CRAM-MD5 or APOP authentication with Auth-Wait response
References

Affected packages

TuxCare:AlmaLinux:9.2
nginx

Package

Name
nginx
Purl
pkg:rpm/tuxcare/nginx?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.20.1-14.el9_2.1.alma.1.tuxcare.els7

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1777022242.json"
nginx-all-modules

Package

Name
nginx-all-modules
Purl
pkg:rpm/tuxcare/nginx-all-modules?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.20.1-14.el9_2.1.alma.1.tuxcare.els7

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1777022242.json"
nginx-core

Package

Name
nginx-core
Purl
pkg:rpm/tuxcare/nginx-core?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.20.1-14.el9_2.1.alma.1.tuxcare.els7

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1777022242.json"
nginx-filesystem

Package

Name
nginx-filesystem
Purl
pkg:rpm/tuxcare/nginx-filesystem?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.20.1-14.el9_2.1.alma.1.tuxcare.els7

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1777022242.json"
nginx-mod-devel

Package

Name
nginx-mod-devel
Purl
pkg:rpm/tuxcare/nginx-mod-devel?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.20.1-14.el9_2.1.alma.1.tuxcare.els7

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1777022242.json"
nginx-mod-http-image-filter

Package

Name
nginx-mod-http-image-filter
Purl
pkg:rpm/tuxcare/nginx-mod-http-image-filter?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.20.1-14.el9_2.1.alma.1.tuxcare.els7

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1777022242.json"
nginx-mod-http-perl

Package

Name
nginx-mod-http-perl
Purl
pkg:rpm/tuxcare/nginx-mod-http-perl?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.20.1-14.el9_2.1.alma.1.tuxcare.els7

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1777022242.json"
nginx-mod-http-xslt-filter

Package

Name
nginx-mod-http-xslt-filter
Purl
pkg:rpm/tuxcare/nginx-mod-http-xslt-filter?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.20.1-14.el9_2.1.alma.1.tuxcare.els7

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1777022242.json"
nginx-mod-mail

Package

Name
nginx-mod-mail
Purl
pkg:rpm/tuxcare/nginx-mod-mail?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.20.1-14.el9_2.1.alma.1.tuxcare.els7

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1777022242.json"
nginx-mod-stream

Package

Name
nginx-mod-stream
Purl
pkg:rpm/tuxcare/nginx-mod-stream?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.20.1-14.el9_2.1.alma.1.tuxcare.els7

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1777022242.json"