Ubuntu alert USN-8398-4 (nginx)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8398-4] nginx vulnerability | |
| Date: | Thu, 02 Jul 2026 18:21:17 +0000 | |
| Message-ID: | <E1wfM2H-0001er-AO@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8398-4 July 02, 2026 nginx vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: nginx could be made to consume excessive resources if it received specially crafted network traffic. Software Description: - nginx: small, powerful, scalable web/proxy server Details: USN-8398-3 fixed a vulnerability in nginx. This update provides the corresponding fix for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that nginx incorrectly handled certain cookie headers in the HTTP/2 implementation. A remote attacker could possibly use this issue to cause nginx to consume excessive resources, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS nginx 1.18.0-0ubuntu1.7+esm3 Available with Ubuntu Pro nginx-common 1.18.0-0ubuntu1.7+esm3 Available with Ubuntu Pro nginx-core 1.18.0-0ubuntu1.7+esm3 Available with Ubuntu Pro nginx-extras 1.18.0-0ubuntu1.7+esm3 Available with Ubuntu Pro nginx-full 1.18.0-0ubuntu1.7+esm3 Available with Ubuntu Pro nginx-light 1.18.0-0ubuntu1.7+esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS nginx 1.14.0-0ubuntu1.11+esm4 Available with Ubuntu Pro nginx-core 1.14.0-0ubuntu1.11+esm4 Available with Ubuntu Pro nginx-extras 1.14.0-0ubuntu1.11+esm4 Available with Ubuntu Pro nginx-full 1.14.0-0ubuntu1.11+esm4 Available with Ubuntu Pro nginx-light 1.14.0-0ubuntu1.11+esm4 Available with Ubuntu Pro Ubuntu 16.04 LTS nginx 1.10.3-0ubuntu0.16.04.5+esm9 Available with Ubuntu Pro nginx-common 1.10.3-0ubuntu0.16.04.5+esm9 Available with Ubuntu Pro nginx-core 1.10.3-0ubuntu0.16.04.5+esm9 Available with Ubuntu Pro nginx-extras 1.10.3-0ubuntu0.16.04.5+esm9 Available with Ubuntu Pro nginx-full 1.10.3-0ubuntu0.16.04.5+esm9 Available with Ubuntu Pro nginx-light 1.10.3-0ubuntu0.16.04.5+esm9 Available with Ubuntu Pro Ubuntu 14.04 LTS nginx 1.4.6-1ubuntu3.9+esm8 Available with Ubuntu Pro nginx-common 1.4.6-1ubuntu3.9+esm8 Available with Ubuntu Pro nginx-core 1.4.6-1ubuntu3.9+esm8 Available with Ubuntu Pro nginx-extras 1.4.6-1ubuntu3.9+esm8 Available with Ubuntu Pro nginx-full 1.4.6-1ubuntu3.9+esm8 Available with Ubuntu Pro nginx-light 1.4.6-1ubuntu3.9+esm8 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8398-4 https://ubuntu.com/security/notices/USN-8398-3 https://ubuntu.com/security/notices/USN-8398-2 https://ubuntu.com/security/notices/USN-8398-1 CVE-2026-49975
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmpGhkoACgkQcpJm3tlz hgHBQQ/+N6vJq7j2a4CJHuYqBPCUUo9H+tinv+VCcL+LXCAKaQeHN/Dd7Epgw30y AQjmKNDPgcEcM934+FhLIU/h60IpWr+WRIZW5Z77CeBn04Lgcn3A5HbFBPsOsGMz fbWeHdriM5XTQVMRyudCIbhu4QxtEt2E5tMbxcSvRrpWQfcdnGmzxyMzZlKQHwQR smyzv/9Y93YLa6iWllK7Nk5Ae80x5Df6DfSB7RcVfJSehh7jen6Ss4NdPogQ0bgo OfuRNnfXKwZgFkgs5eB8UR1ZFe+QS8IFcEy/gIUvTN93SiS5Ixk3Au9F9OElAAvc wOInZ42X1hUff8KnKSEsGhc6kiYU4p6SgxzvTHHLACXv7Ate4XtoIBIGxNeLqE7J WD4UeHzUucE0npcg6nbUdZi4Ze9TvwczJneSpncuQmAI50DbH+VZKTehEb0Qt4+I G77emSb/zky2CA6h4YHLsGwdeD0h7JucRhIrnaobGh4T+pK71R8gO+5XPpuKzKqf yCxEbxC41y2eNhi9QIkIYtGfX8/D4ROKQOvDRhBrP2/sl4onbknwbV8+ndSbn4y8 pqaMWxkJsO+0w7nM8wTjjitEc3Mr+V+qn4mgKBSd660wA+bUglTYRtOdrm8nPlwc fizWjvOxnIv/+uY2aUDvXECUgeEPH8tP9N6CLa4aU7gw6Z6Uc9M= =R4XJ -----END PGP SIGNATURE-----
