"nginx":"1.24" nginx-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1

エラータID: AXSA:2026-1679:01

Release date: 
Thursday, August 27, 2026 - 19:28
Subject: 
"nginx":"1.24" nginx-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage.

Security Fix(es):

* nginx: NGINX: Heap buffer over-read allows memory modification or denial of service (CVE-2026-56434)
* nginx: NGINX: Memory disclosure and denial of service in ngx_http_slice_module (CVE-2026-60005)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-56434
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-60005
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Modularity name: "nginx"
Stream name: "1.24"

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. nginx-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1.src.rpm
    MD5: e65aa658fbc06d839451ae72143c879f
    SHA-256: b6a5188c66fe9ccf766b4c5e3db21f9e0964de5c27aefba6fedd940a70bf2320
    Size: 1.12 MB

Asianux Server 8 for x86_64
  1. nginx-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1.x86_64.rpm
    MD5: 6deee90657cf8c46782abe1905b8a8e7
    SHA-256: ab570de0e4a93fdd731d993f9c0dd29d0531e2b3a1c2ca011316d005ffc820c5
    Size: 601.70 kB
  2. nginx-all-modules-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1.noarch.rpm
    MD5: 83d4b06202055808f43bac222e3466b0
    SHA-256: 94aa0f3cdf24aef2add614870c869978be78920ec43d32ba745168d4d38a43c8
    Size: 26.21 kB
  3. nginx-debugsource-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1.x86_64.rpm
    MD5: a40063f34c40ef33d06cfc16cd994f27
    SHA-256: 5f71c3157d0882e970ac40bfdec5367600945df079c8144064c1377b21c2907d
    Size: 699.19 kB
  4. nginx-filesystem-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1.noarch.rpm
    MD5: 9973747247f593d44600df03bfa9093b
    SHA-256: 14cf9a53a549216f3e04acd5fc0001c23142488d09d78390b634c22ade63b4dd
    Size: 27.18 kB
  5. nginx-mod-devel-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1.x86_64.rpm
    MD5: c57bfabe8cff673855d43e622fc18f62
    SHA-256: f18f8894064bffc50fbad210e85ca1fe8f38971fa08cfb1142e1034e987f3635
    Size: 968.38 kB
  6. nginx-mod-http-image-filter-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1.x86_64.rpm
    MD5: 0226561b4d16f36b95608bc25ee4d73d
    SHA-256: 3e7a2ddb77171cf83bfad35345424d4ae16f9c007564eadb9aff352a912706f5
    Size: 37.61 kB
  7. nginx-mod-http-perl-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1.x86_64.rpm
    MD5: b31a34c7f0c17f0f5a23a117b255dc46
    SHA-256: a8d6f7ba88dd64a4417be64e205d19e0af9ca270473f04540d7d8f48d9a2e861
    Size: 49.39 kB
  8. nginx-mod-http-xslt-filter-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1.x86_64.rpm
    MD5: 9f5332f870fe0c3c5ac52bb9b70d1967
    SHA-256: aba84527cdc5d3c3fedd1b07ede09e52f02f1f80a71751dd8840d94f222ec6c1
    Size: 36.24 kB
  9. nginx-mod-mail-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1.x86_64.rpm
    MD5: 6a7cd5df3ea314b67984f7ec9a518ab9
    SHA-256: d280d045e3356933a0e281026121588265bd7161d99fc7ff3733105197a50f73
    Size: 69.88 kB
  10. nginx-mod-stream-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1.x86_64.rpm
    MD5: 476d17d4230f62e9fdcdb9e9b012b98f
    SHA-256: ae2ac51e5d6843357d7154d7f1ea2d30705ee82e7136f8567584bfaeb10e780b
    Size: 96.86 kB