Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 567
Alerts This Week
Warning Icon 1 567

Mageia 10, 9 nginx Important Heap Overflow & Memory Disclosure 2026-0301

mageia
Calendar Grey July 27, 2026
Scroller Mageia
Mageia security update addresses multiple CVEs related to nginx with risks of memory disclosure and buffer overflow issues.
Three security vulnerabilities in Mageia 10 and 9 related to nginx could lead to heap buffer overflows, memory disclosure, and use-after-free errors, affecting worker processes.

Summary

Description: CVE-2026-42533: Heap buffer overflow might occur in a worker process when using the map directive with regex matching if the map variable was included in a string expression after a capture affected by this map; a similar issue might happen when using a non-cacheable variable in a string expression. Thanks to Mufeed VH of Winfunc Research and Maxim Dounin. . CVE-2026-60005: Uninitialized memory access might occur when using unnamed regex captures with the "slice" directive or background cache update, which could result in worker process memory disclosure or worker process termination. . CVE-2026-56434: Use-after-free might occur when processing a specially crafted proxied backend response with the ngx_http_ssi_filter_module. Thanks to P4P3R-HAK.

References

- https://bugs.mageia.org/show_bug.cgi?id=35973

- https://my.f5.com/manage/s/article/K000162097

- https://my.f5.com/manage/s/article/K000162100

- https://my.f5.com/manage/s/article/K000162098

- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/LIWPH3EULRVLC6TMLBZYPJ5IKQGVF6C2/

- https://www.cve.org/CVERecord?id=CVE-2026-42533

- https://www.cve.org/CVERecord?id=CVE-2026-56434

- https://www.cve.org/CVERecord?id=CVE-2026-60005

Resolution

SRPMS

- 10/core/nginx-1.30.4-1.mga10

- 9/core/nginx-1.30.4-1.mga9

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 27 Jul 2026 
URL: https://advisories.mageia.org/MGASA-2026-0301.html
Type: security
CVE: CVE-2026-42533, CVE-2026-56434, CVE-2026-60005

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.