Ubuntu alert USN-8038-1 (nginx)
| From: | noreply+usn-bot@canonical.com | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8038-1] nginx vulnerability | |
| Date: | Thu, 12 Feb 2026 23:46:18 +0000 | |
| Message-ID: | <E1vqgO2-0005oN-A0@lists.ubuntu.com> |
========================================================================== Ubuntu Security Notice USN-8038-1 February 12, 2026 nginx vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: nginx could be made to insert content into proxied server data. Software Description: - nginx: small, powerful, scalable web/proxy server Details: It was discovered that nginx incorrectly handled proxying to upstream TLS servers. An attacker could possibly use this issue to insert plain text data into the response from an upstream proxied server. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 nginx 1.28.0-6ubuntu1.1 nginx-core 1.28.0-6ubuntu1.1 nginx-extras 1.28.0-6ubuntu1.1 nginx-full 1.28.0-6ubuntu1.1 nginx-light 1.28.0-6ubuntu1.1 Ubuntu 24.04 LTS nginx 1.24.0-2ubuntu7.6 nginx-core 1.24.0-2ubuntu7.6 nginx-extras 1.24.0-2ubuntu7.6 nginx-full 1.24.0-2ubuntu7.6 nginx-light 1.24.0-2ubuntu7.6 Ubuntu 22.04 LTS nginx 1.18.0-6ubuntu14.8 nginx-core 1.18.0-6ubuntu14.8 nginx-extras 1.18.0-6ubuntu14.8 nginx-full 1.18.0-6ubuntu14.8 nginx-light 1.18.0-6ubuntu14.8 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8038-1 CVE-2026-1642 Package Information: https://launchpad.net/ubuntu/+source/nginx/1.28.0-6ubuntu1.1 https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.6 https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmmOZd8ACgkQcpJm3tlz hgGqNxAAgIzZzYA6/abL9h1YLzoA84WRp+Rm7z1iEQ3qSsr2JNTF5wydYts61A6O NbGDzztrsu7gxuP1StZv8h7ofpuI98gwpAM3HSQ4jjQr3OsAp5ucLgYnJbo83rkZ gNNejI+ue7f73OR+M+K2fyhOPqXrYAQdodb2ZYyj+kqMIhpTaldEOJdJi+xkU+sX 95EFBuSdCi7oIJ39MMa2UoAsotY57AQ+T9I6oPrHAiUzwe0Bzc8h0xn41FihnlIe pvNlbHWOrzwVkRGZ0OtjYJFUK6orCzmJq/J9yemMeBuKDXsiIbJvKTzvh9EN0H4J /MM6hcakkwt29cJjRgS9/BJkXL7MOufXgJW2JpcpxqW46IqZ6Fb7YIn5tYWZh4HS epxGmBX7Jz8zsgMvSxwK1H8Zt001rSFwSGEDgnRe2Y4pdyA/VI866OMSkTSKppwx kEnCKd2Wotg9D4nLeYNttcaA88kWhwtsVDqCmeqE61bJYeLV8UowOE+c1Lz1sBTK mY0n2O3+NbH/7AQy1IXXEmsCqJTtpaqGXzAcjpOYcB2zLT+4qaSQEwZg/17uyvQI gdgBkacTck40y7HeRsbTVWfLgKtF7jiKmFS2FkejHv+5nIGClXNpPPzZXdQHn71R oM4wNrjCDf/01L0ndP2a3l6NGX+T9eKFOsGJr5XezACP8iT3VK4= =zrI7 -----END PGP SIGNATURE-----
