Ubuntu alert USN-8458-1 (nginx)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8458-1] nginx vulnerabilities | |
| Date: | Mon, 22 Jun 2026 15:34:56 +0000 | |
| Message-ID: | <E1wbgfo-0006sW-B4@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8458-1 June 22, 2026 nginx vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in nginx. Software Description: - nginx: small, powerful, scalable web/proxy server Details: It was discovered that nginx incorrectly handled large headers when proxying HTTP/2 traffic. A remote attacker could use this issue to cause nginx to crash, resulting in a denial of service, or possibly execute arbitrary code. The default compiler options for affected releases should reduce the vulnerability to a denial of service. (CVE-2026-42055) It was discovered that nginx incorrectly handled character set conversion under certain circumstances. A remote attacker could possibly use this issue to obtain sensitive information or cause nginx to crash, resulting in a denial of service. (CVE-2026-48142) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS nginx 1.28.3-2ubuntu1.6 nginx-core 1.28.3-2ubuntu1.6 nginx-extras 1.28.3-2ubuntu1.6 nginx-full 1.28.3-2ubuntu1.6 nginx-light 1.28.3-2ubuntu1.6 Ubuntu 25.10 nginx 1.28.0-6ubuntu1.8 nginx-core 1.28.0-6ubuntu1.8 nginx-extras 1.28.0-6ubuntu1.8 nginx-full 1.28.0-6ubuntu1.8 nginx-light 1.28.0-6ubuntu1.8 Ubuntu 24.04 LTS nginx 1.24.0-2ubuntu7.13 nginx-core 1.24.0-2ubuntu7.13 nginx-extras 1.24.0-2ubuntu7.13 nginx-full 1.24.0-2ubuntu7.13 nginx-light 1.24.0-2ubuntu7.13 Ubuntu 22.04 LTS nginx 1.18.0-6ubuntu14.16 nginx-core 1.18.0-6ubuntu14.16 nginx-extras 1.18.0-6ubuntu14.16 nginx-full 1.18.0-6ubuntu14.16 nginx-light 1.18.0-6ubuntu14.16 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8458-1 CVE-2026-42055, CVE-2026-48142 Package Information: https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.6 https://launchpad.net/ubuntu/+source/nginx/1.28.0-6ubuntu1.8 https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu... https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmo5TdcACgkQcpJm3tlz hgHmmA/+Np5dPyrA6FKPiQojlIh9e5/7cA/nftNjsKdBqpgR1edXguEo+c0CD8WX cs1BJHm0lQo5NVxeFX3Ze/8jnYb1gf90Yw8yH75iMPjBgmC7FP0T7+NhP63o/Qeb ZUX62oCPqknuGwESplqIBMEC7QPmvedeCPri2IjERpPLtYDtN4x1Wz+lYyD58h5j BbPMzYgWLr1wIOOIC9YEYymoJtnZlAvSbIzGMqPROKDgb8WGRqfE/TNUqUx71/BX yuySs9fhG5XLmVz4ztDo3qJWg7xWwVq0YNWUV97ic0J/SkuQPIAY2Q/WcnPT+41X vj9I7S0dxX/V3+fcLmAjK2Dkavc3xeySOthqYiGlxDxell0NslMRe6S58C/qiyzi UxWhbxuTW3eSkZa9VOIbSn9998qJ8Y+RoUbERzirdExymxsFHJu07LLXULjI6wBN U7hNSc/1+FlLDpTFMuGrzhHgCNt+3DEH0y83bdmuM6AE5TtoblIXBmXWVMBUl/UW M4tINCIj6R1CHimzOJ0id+6ruXwianWISn3CkuQfgJhx9FfeXi5tRbmdSkr/NmzC UQalIuDiJnwZd0t+HjLBlddFKaMXxHhN3MaKY8p1qxbERB43JoBPMDzCEtzyEiqN M7v6b8KGTauO0DLjtPvZpzWTH8K1LCQZPCQGKv46YFOKj5p+ugE= =ejlK -----END PGP SIGNATURE-----
