Debian alert DLA-4667-1 (nginx)
| From: | Carlos Henrique Lima Melara <charles@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4667-1] nginx security update | |
| Date: | Fri, 03 Jul 2026 18:39:15 -0300 | |
| Message-ID: | <akgr8CL8uHp3i6jL@fw13.lan> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-4667-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Carlos Henrique Lima Melara July 03, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : nginx Version : 1.22.1-9+deb12u9 CVE ID : CVE-2026-42055 CVE-2026-48142 Debian Bug : 1140359 1140361 Multiple vulnerabilities were discoverd in Nginx, a high-performance web and reverse proxy server, which could result in remote code execution, denial of service or memory disclosure. CVE-2026-42055 NGINX Open Source has a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. CVE-2026-48142 NGINX Open Source has a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. For Debian 12 bookworm, these problems have been fixed in version 1.22.1-9+deb12u9. We recommend that you upgrade your nginx packages. For the detailed security status of nginx please refer to its security tracker page at: https://security-tracker.debian.org/tracker/nginx Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEECgzx8d8+AINglLHJt4M9ggJ8mQsFAmpILAIACgkQt4M9ggJ8 mQs5PQ/5AWZwLiMrps+VVrQeVZ2zFX3Oy1pUvEzIS8q4B6yZmSjmJd2xMq2BKo2t XUUEeUuQsLqL+RBiqVOnf5CuFLfuglcvhstHwC/BcypfzSuejenT6keZZNgY/aF6 VU5p9UZIWbCfkSg1wNShwcbw46TmWYADn250C5MZmcrnavwseNmp0RwdrMMRtR8v UX6D7UuMkN4Ov0i/iLOY8XmskAmuXgGMsdGlwifztDbi1l+Xgi3Vj91aeljInGqA lkQXKtdvAEGM0Fifk2htsCexioTnXBHYi7qGigc5JTqV/Q+4+yzRWSdtA70cz1cy 0T/tKWTriyQm+68xh54VmM+9VlLF04RGaz98YX+nqifzTpSeTW8fScF1qaQ2EdZQ lGPu0safeXJkJ0JpjIs9xnZCwMFLYLON+4tLPdHRg6IAuTpHZlEXe5DTgG35hoLa 9SGzTXA6gYPRwQEn4qfh3TF9mweH4/QCq+m76wHSeTydSdd0zkVhPnClieW6WT0E YkC5s6atUmcU74gowazagwZztdHUZnBQO6UalcX/ir1wP1c4/atyaUs1VeUn6SZ8 afTROBmZ/XjbSvwUL9EPtbpi/pjIhsYthPOSdRN/xHhY1UPU/h3FPgYMkAstaqGs lxffypZa7cI27MYx6Cdh/OmxZJB3L9/HHope0QiiELRmax1uESY= =+428 -----END PGP SIGNATURE-----
