Debian alert DLA-4660-1 (nginx)
| From: | Carlos Henrique Lima Melara <charles@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4660-1] nginx security update | |
| Date: | Tue, 30 Jun 2026 23:59:41 -0300 | |
| Message-ID: | <akSCjzXaMj_RnHuK@fw13.lan> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-4660-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Carlos Henrique Lima Melara June 30, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : nginx Version : 1.18.0-6.1+deb11u8 CVE ID : CVE-2026-42055 CVE-2026-48142 Debian Bug : 1138794 1140359 1140361 Multiple vulnerabilities were discoverd in Nginx, a high-performance web and reverse proxy server, which could result in remote code execution, denial of service or memory disclosure. CVE-2026-42055 NGINX Open Source has a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. CVE-2026-48142 NGINX Open Source has a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. No CVE assigned yet HTTP/2 Bomb denial of service For Debian 11 bullseye, these problems have been fixed in version 1.18.0-6.1+deb11u8. We recommend that you upgrade your nginx packages. For the detailed security status of nginx please refer to its security tracker page at: https://security-tracker.debian.org/tracker/nginx Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEECgzx8d8+AINglLHJt4M9ggJ8mQsFAmpEgpgACgkQt4M9ggJ8 mQuiThAAopxe9IPUFZjqo/ZOt/nUHaujwFF3wrfZrYu8IFKh0yo5sG6lyrV5YqWw CzOxUUmL3PaUgi8SdMzzRMbP6hWP473Rjif136MQDi07+iOPWw6WVqKwCK8yJbF4 qVTzusp7vIkB9ZLOADoUnYgRUg9H8MlaXx3Of+ihNMH9xVf64p/maM15Kt+bJ+78 6iC91IPPN6T2+JO+5w0sOZGNmDk1zxAHVk4NLxevjhNNMmtOj0W49pLRPf2xtlZl VXGnxZPnIARdPrCnQVCsdl+WMLthpQV4magYax2FhG40HSmPEJEk4oo/zB0OEM0n TfFhRJHBaTH+NQ+shKIXJ7ksYNgoHWH2VVLlifh+HMRm7jN3/klwFiR9olCw21le cBDVPCB8z27Fucuyyq318mG7I6hbgqGaNS93igerHBnrgt1G0OUd9rYHcOK7c5zH gLd1o7vfkRAFQBL9Em5owi6ZO8y+BnZhS9ldHG+eGJ2ofEz2Up23/4MKFRr6xXE5 Lkm1vUTCvTW9JUCJHkEvaNGFMQ+GUIL4kUo88vNvejG4LATWYFN3AXBrctlnrZ77 0P8G3qiawZdwQQWy2DU0iAbhAI5TzQI9O2jEVcfvjjZhVW7/sg4O0SY/t+VtrzVc dmwEgV4NBf94xX/UpTv68g9L+3q4w2H30jntItjYpEX5We/L6No= =9kFR -----END PGP SIGNATURE-----
