nginx-1.20.1-28.el9_8.5.ML.1

エラータID: AXSA:2026-1735:07

Release date: 
Wednesday, September 2, 2026 - 17:09
Subject: 
nginx-1.20.1-28.el9_8.5.ML.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage.

Security Fix(es):

* nginx: NGINX: Heap buffer over-read allows memory modification or denial of service (CVE-2026-56434)
* nginx: NGINX: Memory disclosure and denial of service in ngx_http_slice_module (CVE-2026-60005)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-56434
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-60005
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. nginx-1.20.1-28.el9_8.5.ML.1.src.rpm
    MD5: edb7ec626f924d015fb317071ee39be7
    SHA-256: 4a24256c461bb0a79b991977e3a26a7b19c8ddbb7bcbc775ca165aa0ca5eab8a
    Size: 1.09 MB

Asianux Server 9 for x86_64
  1. nginx-1.20.1-28.el9_8.5.ML.1.x86_64.rpm
    MD5: 0ae4e254358c762fadf7a9f0ad424f16
    SHA-256: 1408b36323395b5fb7417b4ff99bbb44dba6a0d93da6c846442331a0b7794b6e
    Size: 37.88 kB
  2. nginx-all-modules-1.20.1-28.el9_8.5.ML.1.noarch.rpm
    MD5: 36af0ea2095186fc4e86dc4e2f9faafa
    SHA-256: 1c5781b995daf1a45a574125a6f82e6abe447564f47f21560fd58d7368756865
    Size: 9.56 kB
  3. nginx-core-1.20.1-28.el9_8.5.ML.1.x86_64.rpm
    MD5: c68b58130cd00870753af1cb76a528c9
    SHA-256: d00cc74b62a56889f58f91bd238ca3dc22bf199cb0394c10883ade4d77de04e7
    Size: 575.00 kB
  4. nginx-filesystem-1.20.1-28.el9_8.5.ML.1.noarch.rpm
    MD5: 464102fba129c01540e317f3ce576a43
    SHA-256: 3a1f1f82b1c8711abf0412d56dfbfad49715e2cb0e653dbba28742a65c92ce34
    Size: 11.13 kB
  5. nginx-mod-devel-1.20.1-28.el9_8.5.ML.1.x86_64.rpm
    MD5: 5c514f9fb54bffefeff8ca2481e2d885
    SHA-256: 082b95f41431e2d6c495aa015119eabf0729e6e8082210e6945761beb1389ce4
    Size: 837.77 kB
  6. nginx-mod-http-image-filter-1.20.1-28.el9_8.5.ML.1.x86_64.rpm
    MD5: 19a6949f39140139a7179dfe9dfa61f4
    SHA-256: a8d794f5f5176fef9ad8ef314b6558418c7e4f5c41ece4c6960b48220f034606
    Size: 21.23 kB
  7. nginx-mod-http-perl-1.20.1-28.el9_8.5.ML.1.x86_64.rpm
    MD5: 3e8fdafc448ac34f577b8fd2a70e9b77
    SHA-256: 460d0b73842090b60ba79ab627c530ab70dc4dde63164447817a64bfb23cd43d
    Size: 32.64 kB
  8. nginx-mod-http-xslt-filter-1.20.1-28.el9_8.5.ML.1.x86_64.rpm
    MD5: 998527155e8534b40c67ef0db8450444
    SHA-256: 00853f2689540404939b429c30572d766e36538d1823ff58612f19856d9a058c
    Size: 19.98 kB
  9. nginx-mod-mail-1.20.1-28.el9_8.5.ML.1.x86_64.rpm
    MD5: ef17feacc2f73644659213952ad7d0d0
    SHA-256: a360ca7d3bc139045978dfac25b67d370e75eefbaaa11a8b4dc60b7d3dd8c4f6
    Size: 53.61 kB
  10. nginx-mod-stream-1.20.1-28.el9_8.5.ML.1.x86_64.rpm
    MD5: 4fb90f8549fff9a4f897feb23a863fb3
    SHA-256: 3b3f5a47d7377c5baada13aa8404a8eee83dca9ee7d46b8212615c43595258d0
    Size: 78.79 kB