Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

openSUSE NGINX Important Patch Buffer Overflow Advisory 2026-20784-1

opensuse
Calendar Grey May 25, 2026
Dist Opensuse Esm H88
openSUSE releases critical nginx update addressing multiple issues and important vulnerabilities. Check security advisories for details.
An update that solves 5 vulnerabilities and has 5 bug fixes can now be installed.

Description

This update for nginx fixes the following issues:

- CVE-2026-1642: plain text data injection into the response from an upstream proxied server (bsc#1257675).

- CVE-2026-27654: buffer overflow in the NGINX worker process via the `ngx_http_dav_module module` (bsc#1260416).

- CVE-2026-27784: NGINX worker memory over-read or over-write via a specially crafted MP4 file (bsc#1260417).

- CVE-2026-28753: improper handling onf CRLF sequences in CRLF responses allows for arbitrary header injection into SMTP

upstream requests (bsc#1260418).

- CVE-2026-28755: TLS handshakes can succeed with revoked certificates due to improper handling of such certificates by

the `ngx_stream_ssl_module` module (bsc#1260419).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

nginx-1.27.2-160000.3.1

nginx-source-1.27.2-160000.3.1

References

* bsc#1257675

* bsc#1260416

* bsc#1260417

* bsc#1260418

* bsc#1260419

References:

* https://www.suse.com/security/cve/CVE-2026-1642.html

* https://www.suse.com/security/cve/CVE-2026-27654.html

* https://www.suse.com/security/cve/CVE-2026-27784.html

* https://www.suse.com/security/cve/CVE-2026-28753.html

* https://www.suse.com/security/cve/CVE-2026-28755.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:20784-1
Rating: important
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here