Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 455
Alerts This Week
Warning Icon 1 455

Oracle Linux 10 nginx Critical Denial of Service Fix ELSA-2026-19159

oracle
Calendar Grey July 22, 2026
Scroller Oracle
Enhanced security for Oracle Linux 10 with critical nginx updates addressing severe Denial of Service risks. Patch now!
Oracle Linux released security updates for nginx related to multiple vulnerabilities, including arbitrary code execution and denial of service, across various architectures in vers...

Summary

[1.26.3-6.0.1.el10_2.5] - Reference oracle-indexhtml within Requires [Orabug: 33802044] [2:1.26.3-6.5] - Resolves: RHEL-191778 - nginx: "HTTP/2 bomb" nginx fix breaks module ABI causing crashes - Resolves: RHEL-188402 - nginx: NGINX: Arbitrary code execution or. Denial of Service via heap-based buffer overflow with crafted HTTP/2 headers (CVE-2026-42055) [2:1.26.3-6.4] - Resolves: RHEL-178669 - nginx: code execution and denial of service (CVE-2026-9256) - Resolves: RHEL-182544 - nginx: HTTP/2: Remote Denial of Service via compression bomb and Slowloris-style attack [2:1.26.3-6.3] - Resolves: RHEL-176231 - nginx: NGINX: Arbitrary Code Execution Vulnerability (CVE-2026-42945) [2:1.26.3-6.2] - rebuild for the right candidate tag [2:1.26.3-6.1] - RHEL-159547 CVE-2026-27654 nginx: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module - RHEL-159526 CVE-2026-27784 nginx: NGINX: Denial of Service due to memory corruption via crafted MP4 f...

Read the Full Advisory

SRPMs

http://oss.oracle.com/ol10/SRPMS-updates/nginx-1.26.3-6.0.1.el10_2.5.src.rpm

x86_64

nginx-1.26.3-6.0.1.el10_2.5.x86_64.rpm nginx-all-modules-1.26.3-6.0.1.el10_2.5.noarch.rpm nginx-core-1.26.3-6.0.1.el10_2.5.x86_64.rpm nginx-filesystem-1.26.3-6.0.1.el10_2.5.noarch.rpm nginx-mod-devel-1.26.3-6.0.1.el10_2.5.x86_64.rpm nginx-mod-http-image-filter-1.26.3-6.0.1.el10_2.5.x86_64.rpm nginx-mod-http-perl-1.26.3-6.0.1.el10_2.5.x86_64.rpm nginx-mod-http-xslt-filter-1.26.3-6.0.1.el10_2.5.x86_64.rpm nginx-mod-mail-1.26.3-6.0.1.el10_2.5.x86_64.rpm nginx-mod-stream-1.26.3-6.0.1.el10_2.5.x86_64.rpm

aarch64

nginx-1.26.3-6.0.1.el10_2.5.aarch64.rpm nginx-all-modules-1.26.3-6.0.1.el10_2.5.noarch.rpm nginx-core-1.26.3-6.0.1.el10_2.5.aarch64.rpm nginx-filesystem-1.26.3-6.0.1.el10_2.5.noarch.rpm nginx-mod-devel-1.26.3-6.0.1.el10_2.5.aarch64.rpm nginx-mod-http-image-filter-1.26.3-6.0.1.el10_2.5.aarch64.rpm nginx-mod-http-perl-1.26.3-6.0.1.el10_2.5.aarch64.rpm nginx-mod-http-xslt-filter-1.26.3-6.0.1.el10_2.5.aarch64.rpm nginx-mod-mail-1.26.3-6.0.1.el10_2.5.aarch64.rpm nginx-mod-stream-1.26.3-6.0.1.el10_2.5.aarch64.rpm

Severity
critical
Lowest
Low
Medium
High
Critical

Related CVEs: CVE-2026-42945

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.