"nginx":"1.24" nginx-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1
エラータID: AXSA:2026-1679:01
nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage.
Security Fix(es):
* nginx: NGINX: Heap buffer over-read allows memory modification or denial of service (CVE-2026-56434)
* nginx: NGINX: Memory disclosure and denial of service in ngx_http_slice_module (CVE-2026-60005)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-56434
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-60005
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Modularity name: "nginx"
Stream name: "1.24"
Update packages.
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
N/A
SRPMS
- nginx-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1.src.rpm
MD5: e65aa658fbc06d839451ae72143c879f
SHA-256: b6a5188c66fe9ccf766b4c5e3db21f9e0964de5c27aefba6fedd940a70bf2320
Size: 1.12 MB
Asianux Server 8 for x86_64
- nginx-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1.x86_64.rpm
MD5: 6deee90657cf8c46782abe1905b8a8e7
SHA-256: ab570de0e4a93fdd731d993f9c0dd29d0531e2b3a1c2ca011316d005ffc820c5
Size: 601.70 kB - nginx-all-modules-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1.noarch.rpm
MD5: 83d4b06202055808f43bac222e3466b0
SHA-256: 94aa0f3cdf24aef2add614870c869978be78920ec43d32ba745168d4d38a43c8
Size: 26.21 kB - nginx-debugsource-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1.x86_64.rpm
MD5: a40063f34c40ef33d06cfc16cd994f27
SHA-256: 5f71c3157d0882e970ac40bfdec5367600945df079c8144064c1377b21c2907d
Size: 699.19 kB - nginx-filesystem-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1.noarch.rpm
MD5: 9973747247f593d44600df03bfa9093b
SHA-256: 14cf9a53a549216f3e04acd5fc0001c23142488d09d78390b634c22ade63b4dd
Size: 27.18 kB - nginx-mod-devel-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1.x86_64.rpm
MD5: c57bfabe8cff673855d43e622fc18f62
SHA-256: f18f8894064bffc50fbad210e85ca1fe8f38971fa08cfb1142e1034e987f3635
Size: 968.38 kB - nginx-mod-http-image-filter-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1.x86_64.rpm
MD5: 0226561b4d16f36b95608bc25ee4d73d
SHA-256: 3e7a2ddb77171cf83bfad35345424d4ae16f9c007564eadb9aff352a912706f5
Size: 37.61 kB - nginx-mod-http-perl-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1.x86_64.rpm
MD5: b31a34c7f0c17f0f5a23a117b255dc46
SHA-256: a8d6f7ba88dd64a4417be64e205d19e0af9ca270473f04540d7d8f48d9a2e861
Size: 49.39 kB - nginx-mod-http-xslt-filter-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1.x86_64.rpm
MD5: 9f5332f870fe0c3c5ac52bb9b70d1967
SHA-256: aba84527cdc5d3c3fedd1b07ede09e52f02f1f80a71751dd8840d94f222ec6c1
Size: 36.24 kB - nginx-mod-mail-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1.x86_64.rpm
MD5: 6a7cd5df3ea314b67984f7ec9a518ab9
SHA-256: d280d045e3356933a0e281026121588265bd7161d99fc7ff3733105197a50f73
Size: 69.88 kB - nginx-mod-stream-1.24.0-3.module+el8+2034+1ca1f0a6.4.ML.1.x86_64.rpm
MD5: 476d17d4230f62e9fdcdb9e9b012b98f
SHA-256: ae2ac51e5d6843357d7154d7f1ea2d30705ee82e7136f8567584bfaeb10e780b
Size: 96.86 kB