[ubuntu/resolute-security] nginx 1.28.3-2ubuntu1.2 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Mon Jun 1 13:32:26 UTC 2026


nginx (1.28.3-2ubuntu1.2) resolute-security; urgency=medium

  * SECURITY UPDATE: HTTP/3 address spoofing
    - debian/patches/CVE-2026-40460.patch: QUIC: avoid assigning unvalidated
      address to new streams in src/event/quic/ngx_event_quic_migration.c.
    - CVE-2026-40460
  * SECURITY UPDATE: resolver use-after-free in OCSP
    - debian/patches/CVE-2026-40701.patch: OCSP: resolve cleanup on connection
      close in src/event/ngx_event_openssl_stapling.c.
    - CVE-2026-40701
  * SECURITY UPDATE: Buffer overread in the ngx_http_charset_module
    - debian/patches/CVE-2026-42934.patch: Charset: fix buffer over-read in
      recode_from_utf8(). in src/http/modules/ngx_http_charset_filter_module.c.
    - CVE-2026-42934
  * SECURITY UPDATE: Buffer overread in the ngx_http_scgi_module and
    ngx_http_uwsgi_module
    - debian/patches/CVE-2026-42946-1.patch: Upstream: reset parsing state after
      invalid status line in src/http/modules/ngx_http_scgi_module.c,
      src/http/modules/ngx_http_uwsgi_module.c.
    - debian/patches/CVE-2026-42946-2.patch: Upstream: fixed parsing of split
      status lines in src/http/modules/ngx_http_proxy_module.c,
      src/http/modules/ngx_http_scgi_module.c,
      src/http/modules/ngx_http_uwsgi_module.c.
    - CVE-2026-42946
  * SECURITY UPDATE: Buffer overflow in the ngx_http_rewrite_module
    - debian/patches/CVE-2026-9256.patch: Rewrite: fix buffer overflow with
      overlapping captures in src/http/ngx_http_script.c.
    - CVE-2026-9256

Date: 2026-05-30 15:12:10.881938+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list