|
|
Log in / Subscribe / Register

Ubuntu alert USN-8398-4 (nginx)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8398-4] nginx vulnerability
Date:  Thu, 02 Jul 2026 18:21:17 +0000
Message-ID:  <E1wfM2H-0001er-AO@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8398-4 July 02, 2026 nginx vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: nginx could be made to consume excessive resources if it received specially crafted network traffic. Software Description: - nginx: small, powerful, scalable web/proxy server Details: USN-8398-3 fixed a vulnerability in nginx. This update provides the corresponding fix for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that nginx incorrectly handled certain cookie headers in the HTTP/2 implementation. A remote attacker could possibly use this issue to cause nginx to consume excessive resources, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS nginx 1.18.0-0ubuntu1.7+esm3 Available with Ubuntu Pro nginx-common 1.18.0-0ubuntu1.7+esm3 Available with Ubuntu Pro nginx-core 1.18.0-0ubuntu1.7+esm3 Available with Ubuntu Pro nginx-extras 1.18.0-0ubuntu1.7+esm3 Available with Ubuntu Pro nginx-full 1.18.0-0ubuntu1.7+esm3 Available with Ubuntu Pro nginx-light 1.18.0-0ubuntu1.7+esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS nginx 1.14.0-0ubuntu1.11+esm4 Available with Ubuntu Pro nginx-core 1.14.0-0ubuntu1.11+esm4 Available with Ubuntu Pro nginx-extras 1.14.0-0ubuntu1.11+esm4 Available with Ubuntu Pro nginx-full 1.14.0-0ubuntu1.11+esm4 Available with Ubuntu Pro nginx-light 1.14.0-0ubuntu1.11+esm4 Available with Ubuntu Pro Ubuntu 16.04 LTS nginx 1.10.3-0ubuntu0.16.04.5+esm9 Available with Ubuntu Pro nginx-common 1.10.3-0ubuntu0.16.04.5+esm9 Available with Ubuntu Pro nginx-core 1.10.3-0ubuntu0.16.04.5+esm9 Available with Ubuntu Pro nginx-extras 1.10.3-0ubuntu0.16.04.5+esm9 Available with Ubuntu Pro nginx-full 1.10.3-0ubuntu0.16.04.5+esm9 Available with Ubuntu Pro nginx-light 1.10.3-0ubuntu0.16.04.5+esm9 Available with Ubuntu Pro Ubuntu 14.04 LTS nginx 1.4.6-1ubuntu3.9+esm8 Available with Ubuntu Pro nginx-common 1.4.6-1ubuntu3.9+esm8 Available with Ubuntu Pro nginx-core 1.4.6-1ubuntu3.9+esm8 Available with Ubuntu Pro nginx-extras 1.4.6-1ubuntu3.9+esm8 Available with Ubuntu Pro nginx-full 1.4.6-1ubuntu3.9+esm8 Available with Ubuntu Pro nginx-light 1.4.6-1ubuntu3.9+esm8 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8398-4 https://ubuntu.com/security/notices/USN-8398-3 https://ubuntu.com/security/notices/USN-8398-2 https://ubuntu.com/security/notices/USN-8398-1 CVE-2026-49975


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmpGhkoACgkQcpJm3tlz hgHBQQ/+N6vJq7j2a4CJHuYqBPCUUo9H+tinv+VCcL+LXCAKaQeHN/Dd7Epgw30y AQjmKNDPgcEcM934+FhLIU/h60IpWr+WRIZW5Z77CeBn04Lgcn3A5HbFBPsOsGMz fbWeHdriM5XTQVMRyudCIbhu4QxtEt2E5tMbxcSvRrpWQfcdnGmzxyMzZlKQHwQR smyzv/9Y93YLa6iWllK7Nk5Ae80x5Df6DfSB7RcVfJSehh7jen6Ss4NdPogQ0bgo OfuRNnfXKwZgFkgs5eB8UR1ZFe+QS8IFcEy/gIUvTN93SiS5Ixk3Au9F9OElAAvc wOInZ42X1hUff8KnKSEsGhc6kiYU4p6SgxzvTHHLACXv7Ate4XtoIBIGxNeLqE7J WD4UeHzUucE0npcg6nbUdZi4Ze9TvwczJneSpncuQmAI50DbH+VZKTehEb0Qt4+I G77emSb/zky2CA6h4YHLsGwdeD0h7JucRhIrnaobGh4T+pK71R8gO+5XPpuKzKqf yCxEbxC41y2eNhi9QIkIYtGfX8/D4ROKQOvDRhBrP2/sl4onbknwbV8+ndSbn4y8 pqaMWxkJsO+0w7nM8wTjjitEc3Mr+V+qn4mgKBSd660wA+bUglTYRtOdrm8nPlwc fizWjvOxnIv/+uY2aUDvXECUgeEPH8tP9N6CLa4aU7gw6Z6Uc9M= =R4XJ -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds