Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 431
Alerts This Week
Warning Icon 1 431

openSUSE NGINX Important Buffer Overflow DoS Vuln 2026-21439-1

opensuse
Calendar Grey July 26, 2026
Scroller Opensuse
An important openSUSE advisory addresses nginx vulnerabilities including a denial of service and buffer overflow issues.
openSUSE has released a security update for nginx addressing three vulnerabilities, including authorization bypass and buffer overflows, along with four bug fixes for openSUSE Leap...

Description

This update for nginx fixes the following issues

- CVE-2026-40460: bypass of authorization and bypass of rate limiting when NGINX is configured to use the HTTP/3 QUIC module (bsc#1265228).

- CVE-2026-42055: heap-based buffer overflow in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules (bsc#1268492).

- CVE-2026-48142: heap buffer over-read in the ngx_http_charset_module module (bsc#1268495).

- HTTP2-BOMB denial of service (bsc#1267525).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1343=1

Patch

Package List

- openSUSE Leap 16.0:

nginx-1.27.2-160000.6.1

nginx-source-1.27.2-160000.6.1

References

* bsc#1265228

* bsc#1267525

* bsc#1268492

* bsc#1268495

References:

* https://www.suse.com/security/cve/CVE-2026-40460.html

* https://www.suse.com/security/cve/CVE-2026-42055.html

* https://www.suse.com/security/cve/CVE-2026-48142.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:21439-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.