[ubuntu/resolute-security] nginx 1.28.3-2ubuntu1.2 (Accepted)
Marc Deslauriers
marc.deslauriers at canonical.com
Mon Jun 1 13:32:26 UTC 2026
nginx (1.28.3-2ubuntu1.2) resolute-security; urgency=medium
* SECURITY UPDATE: HTTP/3 address spoofing
- debian/patches/CVE-2026-40460.patch: QUIC: avoid assigning unvalidated
address to new streams in src/event/quic/ngx_event_quic_migration.c.
- CVE-2026-40460
* SECURITY UPDATE: resolver use-after-free in OCSP
- debian/patches/CVE-2026-40701.patch: OCSP: resolve cleanup on connection
close in src/event/ngx_event_openssl_stapling.c.
- CVE-2026-40701
* SECURITY UPDATE: Buffer overread in the ngx_http_charset_module
- debian/patches/CVE-2026-42934.patch: Charset: fix buffer over-read in
recode_from_utf8(). in src/http/modules/ngx_http_charset_filter_module.c.
- CVE-2026-42934
* SECURITY UPDATE: Buffer overread in the ngx_http_scgi_module and
ngx_http_uwsgi_module
- debian/patches/CVE-2026-42946-1.patch: Upstream: reset parsing state after
invalid status line in src/http/modules/ngx_http_scgi_module.c,
src/http/modules/ngx_http_uwsgi_module.c.
- debian/patches/CVE-2026-42946-2.patch: Upstream: fixed parsing of split
status lines in src/http/modules/ngx_http_proxy_module.c,
src/http/modules/ngx_http_scgi_module.c,
src/http/modules/ngx_http_uwsgi_module.c.
- CVE-2026-42946
* SECURITY UPDATE: Buffer overflow in the ngx_http_rewrite_module
- debian/patches/CVE-2026-9256.patch: Rewrite: fix buffer overflow with
overlapping captures in src/http/ngx_http_script.c.
- CVE-2026-9256
Date: 2026-05-30 15:12:10.881938+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.2
-------------- next part --------------
Sorry, changesfile not available.
More information about the Resolute-changes
mailing list