"nginx":"1.24" nginx-1.24.0-3.module+el8+2045+adfc96b2.5.ML.1
エラータID: AXSA:2026-1852:01
nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage.
Security Fix(es):
* nginx: NGINX: Arbitrary code execution via crafted HTTP requests (CVE-2026-42533)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-42533
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Modularity name: "nginx"
Stream name: "1.24"
Update packages.
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
N/A
SRPMS
- nginx-1.24.0-3.module+el8+2045+adfc96b2.5.ML.1.src.rpm
MD5: 2b366e2dd83668a650acec4779879160
SHA-256: dade055feb053d1b55dc0a8ea78780931b474205c293c64f6c86f690b4c4d62b
Size: 1.13 MB
Asianux Server 8 for x86_64
- nginx-1.24.0-3.module+el8+2045+adfc96b2.5.ML.1.x86_64.rpm
MD5: b49c7a215590c8b4ed4d850a1ceca9c8
SHA-256: 4218865ce543023bb39055c1ce7df99e327d1583e9ae176402d6bb27df01ffba
Size: 603.23 kB - nginx-all-modules-1.24.0-3.module+el8+2045+adfc96b2.5.ML.1.noarch.rpm
MD5: ef4dba31a85a87194e241b83c85d4dca
SHA-256: fe7e0b334d22454ecd7db9392e3fc21d8bbc3d1df5a8a4149174226658efe265
Size: 26.39 kB - nginx-debugsource-1.24.0-3.module+el8+2045+adfc96b2.5.ML.1.x86_64.rpm
MD5: 54fa6d1ed49bf1b39a4ab45280f2bd6e
SHA-256: f4d628d9f04ab67708358f0973b10c9caec1e1086ce848a15fc814e237565976
Size: 700.82 kB - nginx-filesystem-1.24.0-3.module+el8+2045+adfc96b2.5.ML.1.noarch.rpm
MD5: 7046d3dbd0ac9acce417062cd8f87afb
SHA-256: ba4b90e51a975e25bb277e83f3f81e7644c830c48b0c769004698d46f1fe2545
Size: 27.36 kB - nginx-mod-devel-1.24.0-3.module+el8+2045+adfc96b2.5.ML.1.x86_64.rpm
MD5: 6b40f2b28bdf4f93d3bc8ffa68f34a21
SHA-256: 0f8af4f0eaa2230dd113bf2da54bc9334822b41928111ad33a9408f3d90cb036
Size: 970.01 kB - nginx-mod-http-image-filter-1.24.0-3.module+el8+2045+adfc96b2.5.ML.1.x86_64.rpm
MD5: 3ebee76d004bd265c223cbf140978406
SHA-256: 18f2b3f6512e75ceb8de776ebcda5881c99705db1c1de449360677a85f9b4fc7
Size: 37.59 kB - nginx-mod-http-perl-1.24.0-3.module+el8+2045+adfc96b2.5.ML.1.x86_64.rpm
MD5: 8f9e3892400ed00ec094300ce2684579
SHA-256: abda5cf1150756a73c4aea7d74b4c7ce7926460e448625ba426ab9ba2302abc0
Size: 49.35 kB - nginx-mod-http-xslt-filter-1.24.0-3.module+el8+2045+adfc96b2.5.ML.1.x86_64.rpm
MD5: 22bceed957406c764464ed46abe60fa4
SHA-256: ec1f25957757eb018085e18ba9523cf16c92cf29c126ea172b78e2131841718c
Size: 36.22 kB - nginx-mod-mail-1.24.0-3.module+el8+2045+adfc96b2.5.ML.1.x86_64.rpm
MD5: 5d254411e5691a99d64f8900084a4193
SHA-256: 828fb649bfb11ae44517d1dd11704454ef44dbc6fad52530c8106a79442aee87
Size: 69.83 kB - nginx-mod-stream-1.24.0-3.module+el8+2045+adfc96b2.5.ML.1.x86_64.rpm
MD5: 583998b34b51057c9bc9525269f3d13f
SHA-256: 8f3d79e0b95f025ce7731b23f7ba9c68c394d006dfabbc74b660c369f4439a90
Size: 97.38 kB