Ubuntu alert USN-8425-1 (libnginx-mod-js)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8425-1] njs vulnerability | |
| Date: | Wed, 17 Jun 2026 19:43:43 +0000 | |
| Message-ID: | <E1wZwAp-000716-GD@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8425-1 June 11, 2026 libnginx-mod-js vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS Summary: njs could be made to crash or run programs if it received a specially crafted input. Software Description: - libnginx-mod-js: A subset of JavaScript language to use in nginx Details: It was discovered that njs did not properly handle certain client- controlled variables when processing ngx.fetch() requests. An attacker could possibly use this issue to trigger a heap buffer overflow, resulting in arbitrary code execution or a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libnginx-mod-http-js 0.9.4-1ubuntu0.1~esm1 Available with Ubuntu Pro libnginx-mod-stream-js 0.9.4-1ubuntu0.1~esm1 Available with Ubuntu Pro njs 0.9.4-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8425-1 CVE-2026-8711
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmoyvRgACgkQcpJm3tlz hgEX+xAA0zHetw0QtmN6cGUaLWg543GsKQoEhTsxkchSgFYYPpYvUQS6J6/I93MY RRtmaV83PLZl759mEUg4x2g5xOA8vJ5YHTFnmxIaCNJ2bsnHmX2CIjwrPbAa/FV1 9z8e9GADfdZ927asxMpWO6MOazEu1qoObxdSs462+egkJzWRUoZBTrFzQOEzq1J3 W0MeOPX8oEDa/rVuU22FlsOHU18NLGhBntFFxk4e36QvFdLcwsUmLQXBUo9jRbtu UqJd1ncuUGCLOMCWy5t3xCAtWM6OJy9bcTQ8xTUvPRxV2pt051Y1kOU+F7mY0djo HJ9wgi2jjiZ7joqPVP6koLjyf3xmJWVZA2VLhhul4dRshAaWXcWFsNKh6vFKzCNh YFeu08tMplB3JUXJd4hF+8GwCjzp5WQ0MQoeg2zZgpMLVu/Ec9+a6t2YheFCTZmv +KS4cukUqEa++Bcin/4qqGCNDBNqZbh2rQ0xSIw7C+4cemlFEr9v+ZUcc7ykcEAh pwV9rAmHBaTjjcUcCGN43EH2qQA4RytAwI4NXFlFgur+efYWzIMSopVPLBg2QT1z 1DQ2IacVbMmbFmvBjU/ppBP0YReKfaI1pSe3jc0hcDspN1vvjo3mjNW1qA3uKrk5 03fSZ6+ALeAH5Ljf3oqhAnAM9wmICAPTbWYSP9NigjwDcX6nu3M= =8vKN -----END PGP SIGNATURE-----
