[ubuntu/resolute-updates] nginx 1.28.3-2ubuntu1.7 (Accepted)
Ubuntu Archive Robot
ubuntu-archive-robot at lists.canonical.com
Mon Jul 20 19:03:34 UTC 2026
nginx (1.28.3-2ubuntu1.7) resolute-security; urgency=medium
* SECURITY UPDATE: DoS and possible code execution via map directive
- debian/patches/CVE-2026-42533-pre1.patch: Script: simplified copy capture
codes. in src/http/ngx_http_script.c, src/stream/ngx_stream_script.c.
- debian/patches/CVE-2026-42533-1.patch: Script: buffer overrun protection.
in src/http/ngx_http_script.c, src/http/ngx_http_script.h,
src/stream/ngx_stream_script.c, src/stream/ngx_stream_script.h.
- debian/patches/CVE-2026-42533-2.patch: Script: buffer overrun protection
in direct script usage. in src/http/modules/ngx_http_fastcgi_module.c,
src/http/modules/ngx_http_grpc_module.c,
src/http/modules/ngx_http_index_module.c,
src/http/modules/ngx_http_proxy_module.c,
src/http/modules/ngx_http_scgi_module.c,
src/http/modules/ngx_http_try_files_module.c,
src/http/modules/ngx_http_uwsgi_module.c.
- debian/patches/CVE-2026-42533-3.patch: Script: avoid garbage at the end of
the result string in src/http/modules/ngx_http_rewrite_module.c,
src/http/ngx_http_script.c, src/http/ngx_http_script.h,
src/stream/ngx_stream_script.c.
- debian/patches/CVE-2026-42533-4.patch: Access log: buffer overrun
protection. in src/http/modules/ngx_http_log_module.c,
src/stream/ngx_stream_log_module.c.
- CVE-2026-42533
* SECURITY UPDATE: use-after-free in ngx_http_ssi_module module
- debian/patches/CVE-2026-56434.patch: Avoid duplicate subrequest
finalization in src/http/ngx_http_request.c.
- CVE-2026-56434
* SECURITY UPDATE: uninitialized memory access in ngx_http_slice_module
- debian/patches/CVE-2026-60005.patch: Fixed uninitialized memory read
caused by stale regex captures. in src/http/ngx_http_variables.c.
- CVE-2026-60005
Date: 2026-07-16 14:05:11.790004+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7
-------------- next part --------------
Sorry, changesfile not available.
More information about the Resolute-changes
mailing list