nginx-1.20.1-28.el9_8.5.ML.1
エラータID: AXSA:2026-1735:07
nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage.
Security Fix(es):
* nginx: NGINX: Heap buffer over-read allows memory modification or denial of service (CVE-2026-56434)
* nginx: NGINX: Memory disclosure and denial of service in ngx_http_slice_module (CVE-2026-60005)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-56434
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-60005
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Update packages.
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
N/A
SRPMS
- nginx-1.20.1-28.el9_8.5.ML.1.src.rpm
MD5: edb7ec626f924d015fb317071ee39be7
SHA-256: 4a24256c461bb0a79b991977e3a26a7b19c8ddbb7bcbc775ca165aa0ca5eab8a
Size: 1.09 MB
Asianux Server 9 for x86_64
- nginx-1.20.1-28.el9_8.5.ML.1.x86_64.rpm
MD5: 0ae4e254358c762fadf7a9f0ad424f16
SHA-256: 1408b36323395b5fb7417b4ff99bbb44dba6a0d93da6c846442331a0b7794b6e
Size: 37.88 kB - nginx-all-modules-1.20.1-28.el9_8.5.ML.1.noarch.rpm
MD5: 36af0ea2095186fc4e86dc4e2f9faafa
SHA-256: 1c5781b995daf1a45a574125a6f82e6abe447564f47f21560fd58d7368756865
Size: 9.56 kB - nginx-core-1.20.1-28.el9_8.5.ML.1.x86_64.rpm
MD5: c68b58130cd00870753af1cb76a528c9
SHA-256: d00cc74b62a56889f58f91bd238ca3dc22bf199cb0394c10883ade4d77de04e7
Size: 575.00 kB - nginx-filesystem-1.20.1-28.el9_8.5.ML.1.noarch.rpm
MD5: 464102fba129c01540e317f3ce576a43
SHA-256: 3a1f1f82b1c8711abf0412d56dfbfad49715e2cb0e653dbba28742a65c92ce34
Size: 11.13 kB - nginx-mod-devel-1.20.1-28.el9_8.5.ML.1.x86_64.rpm
MD5: 5c514f9fb54bffefeff8ca2481e2d885
SHA-256: 082b95f41431e2d6c495aa015119eabf0729e6e8082210e6945761beb1389ce4
Size: 837.77 kB - nginx-mod-http-image-filter-1.20.1-28.el9_8.5.ML.1.x86_64.rpm
MD5: 19a6949f39140139a7179dfe9dfa61f4
SHA-256: a8d794f5f5176fef9ad8ef314b6558418c7e4f5c41ece4c6960b48220f034606
Size: 21.23 kB - nginx-mod-http-perl-1.20.1-28.el9_8.5.ML.1.x86_64.rpm
MD5: 3e8fdafc448ac34f577b8fd2a70e9b77
SHA-256: 460d0b73842090b60ba79ab627c530ab70dc4dde63164447817a64bfb23cd43d
Size: 32.64 kB - nginx-mod-http-xslt-filter-1.20.1-28.el9_8.5.ML.1.x86_64.rpm
MD5: 998527155e8534b40c67ef0db8450444
SHA-256: 00853f2689540404939b429c30572d766e36538d1823ff58612f19856d9a058c
Size: 19.98 kB - nginx-mod-mail-1.20.1-28.el9_8.5.ML.1.x86_64.rpm
MD5: ef17feacc2f73644659213952ad7d0d0
SHA-256: a360ca7d3bc139045978dfac25b67d370e75eefbaaa11a8b4dc60b7d3dd8c4f6
Size: 53.61 kB - nginx-mod-stream-1.20.1-28.el9_8.5.ML.1.x86_64.rpm
MD5: 4fb90f8549fff9a4f897feb23a863fb3
SHA-256: 3b3f5a47d7377c5baada13aa8404a8eee83dca9ee7d46b8212615c43595258d0
Size: 78.79 kB