nginx-1.20.1-28.el9_8.6.ML.1
エラータID: AXSA:2026-1857:08
nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage.
Security Fix(es):
* nginx: NGINX: Arbitrary code execution via crafted HTTP requests (CVE-2026-42533)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-42533
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Update packages.
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
N/A
SRPMS
- nginx-1.20.1-28.el9_8.6.ML.1.src.rpm
MD5: 5027aa5b298c981bf2cc4c10200f0af3
SHA-256: 1c9dee4e926e9ef91216f6721afb065ba026fa2cebd2b971336834d26f304747
Size: 1.10 MB
Asianux Server 9 for x86_64
- nginx-1.20.1-28.el9_8.6.ML.1.x86_64.rpm
MD5: 5bfc17fae8ed6543351d72796b068ea1
SHA-256: 5f31871d57c4e6b383904788d962fb98008273edfabd247110a6fd964724b18b
Size: 38.04 kB - nginx-all-modules-1.20.1-28.el9_8.6.ML.1.noarch.rpm
MD5: 1bea7c011a32a18ddb93e1ca7df861a7
SHA-256: 5b1ccf4db4777808ac4a1265efca7413ede84549ae4ae7aa8c1aa802a4dcb2d0
Size: 9.72 kB - nginx-core-1.20.1-28.el9_8.6.ML.1.x86_64.rpm
MD5: 4ada116ac297675046ee8c824ec9ddac
SHA-256: 681ade170dc5ad995ff89c166a54509c95e6fa93b927142a4c98ec6d4b71b422
Size: 577.02 kB - nginx-filesystem-1.20.1-28.el9_8.6.ML.1.noarch.rpm
MD5: d5c40dc05e318493da2c3e5da7fa6960
SHA-256: c069d3585d4aa74454a7c510fcbf5d9bc12744084c721d9c40280a92df1a99a8
Size: 11.29 kB - nginx-mod-devel-1.20.1-28.el9_8.6.ML.1.x86_64.rpm
MD5: 43520ecbd3bc826a1c8c55b27f78542e
SHA-256: fbc66c903aaf1d7e75778274267bbb5e30057603e0a9e198d93ffa84442e78b4
Size: 838.51 kB - nginx-mod-http-image-filter-1.20.1-28.el9_8.6.ML.1.x86_64.rpm
MD5: 5df39138d4a6ee38a8c40bb84a727f25
SHA-256: e1033e23a9f430f247c7c340bea79703d6df36cc0b5f0d4f21627d96853a12ae
Size: 21.40 kB - nginx-mod-http-perl-1.20.1-28.el9_8.6.ML.1.x86_64.rpm
MD5: 18564986211e71b65c7199d0fde50fc0
SHA-256: d07dbeb3d6cbc9dbded042c7345d0c0887aae21577d49f3d4dfdd24c2ae49b70
Size: 32.80 kB - nginx-mod-http-xslt-filter-1.20.1-28.el9_8.6.ML.1.x86_64.rpm
MD5: 8b8b95bf7fa1b2bc67b8bd9e2e90d5c7
SHA-256: c5abc27c817243d4710d10269379ad2003a9488db597c8474baddc7a520d09ab
Size: 20.14 kB - nginx-mod-mail-1.20.1-28.el9_8.6.ML.1.x86_64.rpm
MD5: 1531511a2e44b5be79eb562b3b2dceef
SHA-256: 3d7d32144b978eea0b2117a9693e37d648b165ef8b2bd7a9c8e763b70b914603
Size: 53.78 kB - nginx-mod-stream-1.20.1-28.el9_8.6.ML.1.x86_64.rpm
MD5: e2fdccc34481e0d3431dadcd41e9d3e2
SHA-256: ca9dd23395b881f6ccef216e1676f0c901622bc8ad26200cf68bf377535224bd
Size: 79.70 kB