Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 17 articles for you...
100

SUSE nginx Important Memory Overread Buffer Overflow Vuln 2026-1761-1

An update that solves four vulnerabilities can now be installed.. # Security update for nginx Announcement ID: SUSE-SU-2026:1761-1 Release Date: 2026-05-08T08:58:17Z Rating: important References: * bsc#1257675 * bsc#1260416 * bsc#1260417 * bsc#1260418 Cross-References: * CVE-2026-1642 * CVE-2026-27654 * CVE-2026-27784 * CVE-2026-28753 CVSS scores: * CVE-2026-1642 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-1642 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-1642 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-1642 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-27654 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-27654 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-27654 ( NVD ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27654 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-27784 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-27784 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27784 ( NVD ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27784 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27784 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28753 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-28753 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-28753 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-28753 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * openSUSE Leap 15.6 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for nginx fixes the following issues: * CVE-2026-1642: plain text data injection into the response from an upstream proxied server via MITM attack (bsc#1257675). * CVE-2026-27654: buffer overflow in the NGINX worker process via the `ngx_http_dav_module` module (bsc#1260416). * CVE-2026-27784: NGINX worker memory overread or overwrite via a specially crafted MP4 file (bsc#1260417). * CVE-2026-28753: arbitrary header injection into SMTP upstream requests via attacker-controlled DNS server (bsc#1260418). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-1761=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-1761=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patchSUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1761=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1761=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * nginx-debugsource-1.21.5-150600.10.15.1 * nginx-debuginfo-1.21.5-150600.10.15.1 * nginx-1.21.5-150600.10.15.1 * openSUSE Leap 15.6 (noarch) * nginx-source-1.21.5-150600.10.15.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * nginx-debugsource-1.21.5-150600.10.15.1 * nginx-debuginfo-1.21.5-150600.10.15.1 * nginx-1.21.5-150600.10.15.1 * Server Applications Module 15-SP7 (noarch) * nginx-source-1.21.5-150600.10.15.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * nginx-debugsource-1.21.5-150600.10.15.1 * nginx-debuginfo-1.21.5-150600.10.15.1 * nginx-1.21.5-150600.10.15.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * nginx-source-1.21.5-150600.10.15.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * nginx-debugsource-1.21.5-150600.10.15.1 * nginx-debuginfo-1.21.5-150600.10.15.1 * nginx-1.21.5-150600.10.15.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * nginx-source-1.21.5-150600.10.15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-1642.html * https://www.suse.com/security/cve/CVE-2026-27654.html * https://www.suse.com/security/cve/CVE-2026-27784.html * https://www.suse.com/security/cve/CVE-2026-28753.html * https://bugzilla.suse.com/show_bug.cgi?id=1257675 * https://bugzilla.suse.com/show_bug.cgi?id=1260416 * https://bugzilla.suse.com/show_bug.cgi?id=1260417 * https://bugzilla.suse.com/show_bug.cgi?id=1260418 . Critical update released for nginx on SUSE fixes four security issues including buffer overflow and data injection.. SUSE nginx security patch important vulnerabilities buffer overflow. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 08, 2026 Important SuSE
219

Essential Security Patch RLSB-2026-5420 for Ubuntu Server 20 with Nginx

Moderate: nginx:1.24 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:5581", "synopsis": "Moderate: nginx:1.24 security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for module.nginx, nginx.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage. \n\nSecurity Fix(es):\n\n* nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections (CVE-2026-1642)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2436738", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2436738", "description": ""}], "cves": [{"name": "CVE-2026-1642", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-1642", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N", "cvss3BaseScore": "5.9", "cwe": "CWE-349"}], "references": [], "publishedAt": "2026-04-07T00:01:14.755526Z", "rpms": {"Rocky Linux 8": {"nvras": ["nginx-1:1.24.0-2.module+el8.10.0+40137+188e04f4.aarch64.rpm", "nginx-1:1.24.0-2.module+el8.10.0+40137+188e04f4.src.rpm", "nginx-1:1.24.0-2.module+el8.10.0+40137+188e04f4.x86_64.rpm", "nginx-all-modules-1:1.24.0-2.module+el8.10.0+40137+188e04f4.noarch.rpm", "nginx-debuginfo-1:1.24.0-2.module+el8.10.0+40137+188e04f4.aarch64.rpm", "nginx-debuginfo-1:1.24.0-2.module+el8.10.0+40137+188e04f4.x86_64.rpm", "nginx-debugsource-1:1.24.0-2.module+el8.10.0+40137+188e04f4.aarch64.rpm", "nginx-debugsource-1:1.24.0-2.module+el8.10.0+40137+188e04f4.x86_64.rpm","nginx-filesystem-1:1.24.0-2.module+el8.10.0+40137+188e04f4.noarch.rpm", "nginx-mod-devel-1:1.24.0-2.module+el8.10.0+40137+188e04f4.aarch64.rpm", "nginx-mod-devel-1:1.24.0-2.module+el8.10.0+40137+188e04f4.x86_64.rpm", "nginx-mod-http-image-filter-1:1.24.0-2.module+el8.10.0+40137+188e04f4.aarch64.rpm", "nginx-mod-http-image-filter-1:1.24.0-2.module+el8.10.0+40137+188e04f4.x86_64.rpm", "nginx-mod-http-image-filter-debuginfo-1:1.24.0-2.module+el8.10.0+40137+188e04f4.aarch64.rpm", "nginx-mod-http-image-filter-debuginfo-1:1.24.0-2.module+el8.10.0+40137+188e04f4.x86_64.rpm", "nginx-mod-http-perl-1:1.24.0-2.module+el8.10.0+40137+188e04f4.aarch64.rpm", "nginx-mod-http-perl-1:1.24.0-2.module+el8.10.0+40137+188e04f4.x86_64.rpm", "nginx-mod-http-perl-debuginfo-1:1.24.0-2.module+el8.10.0+40137+188e04f4.aarch64.rpm", "nginx-mod-http-perl-debuginfo-1:1.24.0-2.module+el8.10.0+40137+188e04f4.x86_64.rpm", "nginx-mod-http-xslt-filter-1:1.24.0-2.module+el8.10.0+40137+188e04f4.aarch64.rpm", "nginx-mod-http-xslt-filter-1:1.24.0-2.module+el8.10.0+40137+188e04f4.x86_64.rpm", "nginx-mod-http-xslt-filter-debuginfo-1:1.24.0-2.module+el8.10.0+40137+188e04f4.aarch64.rpm", "nginx-mod-http-xslt-filter-debuginfo-1:1.24.0-2.module+el8.10.0+40137+188e04f4.x86_64.rpm", "nginx-mod-mail-1:1.24.0-2.module+el8.10.0+40137+188e04f4.aarch64.rpm", "nginx-mod-mail-1:1.24.0-2.module+el8.10.0+40137+188e04f4.x86_64.rpm", "nginx-mod-mail-debuginfo-1:1.24.0-2.module+el8.10.0+40137+188e04f4.aarch64.rpm", "nginx-mod-mail-debuginfo-1:1.24.0-2.module+el8.10.0+40137+188e04f4.x86_64.rpm", "nginx-mod-stream-1:1.24.0-2.module+el8.10.0+40137+188e04f4.aarch64.rpm", "nginx-mod-stream-1:1.24.0-2.module+el8.10.0+40137+188e04f4.x86_64.rpm", "nginx-mod-stream-debuginfo-1:1.24.0-2.module+el8.10.0+40137+188e04f4.aarch64.rpm", "nginx-mod-stream-debuginfo-1:1.24.0-2.module+el8.10.0+40137+188e04f4.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Update available for nginx on Rocky Linux 8 addressing moderate security issue; mitigate data injection riskseffectively.. nginx security update, Rocky Linux 8, data injection issue. . LinuxSecurity.com Team

Calendar%202 Apr 07, 2026 Rocky Linux
202

openSUSE Leap 15.4 redis Moderate Vulnerability Patch SUSE-2026-1122-1

An update that has one security fix can now be installed.. # Security update for redis Announcement ID: SUSE-SU-2026:1122-1 Release Date: 2026-03-27T14:21:13Z Rating: moderate References: * bsc#1258706 Affected Products: * openSUSE Leap 15.4 An update that has one security fix can now be installed. ## Description: This update for redis fixes the following issue: * a user can manipulate data read by a connection by injecting sequences into a Redis error reply (bsc#1258706). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-1122=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * redis-debuginfo-6.2.6-150400.3.43.1 * redis-debugsource-6.2.6-150400.3.43.1 * redis-6.2.6-150400.3.43.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1258706 . Update for openSUSE fixes moderate issue in redis, addressing data manipulation risks. Install via zypper for safety.. openSUSE Redis security patch. . LinuxSecurity.com Team

Calendar%202 Mar 27, 2026 OpenSUSE
217

Oracle Linux 9 nginx Moderate Data Injection Threat ELSA-2026-5599

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-5599 http://linux.oracle.com/errata/ELSA-2026-5599.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: nginx-1.20.1-24.0.1.el9_7.1.x86_64.rpm nginx-all-modules-1.20.1-24.0.1.el9_7.1.noarch.rpm nginx-core-1.20.1-24.0.1.el9_7.1.x86_64.rpm nginx-filesystem-1.20.1-24.0.1.el9_7.1.noarch.rpm nginx-mod-devel-1.20.1-24.0.1.el9_7.1.x86_64.rpm nginx-mod-http-image-filter-1.20.1-24.0.1.el9_7.1.x86_64.rpm nginx-mod-http-perl-1.20.1-24.0.1.el9_7.1.x86_64.rpm nginx-mod-http-xslt-filter-1.20.1-24.0.1.el9_7.1.x86_64.rpm nginx-mod-mail-1.20.1-24.0.1.el9_7.1.x86_64.rpm nginx-mod-stream-1.20.1-24.0.1.el9_7.1.x86_64.rpm aarch64: nginx-1.20.1-24.0.1.el9_7.1.aarch64.rpm nginx-all-modules-1.20.1-24.0.1.el9_7.1.noarch.rpm nginx-core-1.20.1-24.0.1.el9_7.1.aarch64.rpm nginx-filesystem-1.20.1-24.0.1.el9_7.1.noarch.rpm nginx-mod-devel-1.20.1-24.0.1.el9_7.1.aarch64.rpm nginx-mod-http-image-filter-1.20.1-24.0.1.el9_7.1.aarch64.rpm nginx-mod-http-perl-1.20.1-24.0.1.el9_7.1.aarch64.rpm nginx-mod-http-xslt-filter-1.20.1-24.0.1.el9_7.1.aarch64.rpm nginx-mod-mail-1.20.1-24.0.1.el9_7.1.aarch64.rpm nginx-mod-stream-1.20.1-24.0.1.el9_7.1.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/nginx-1.20.1-24.0.1.el9_7.1.src.rpm Related CVEs: CVE-2026-1642 Description of changes: [1.20.1-24.0.1.el9_7.1] - Reference oracle-indexhtml within Requires [Orabug: 33802044] - Remove Red Hat references [Orabug: 29498217] - Update upstream references [Orabug: 36579090] [2:1.20.1-24.1] - Resolves: RHEL-146525 - nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections (CVE-2026-1642) [2:1.20.1-24] - Resolves: RHEL-84477 - nginx: specially crafted MP4 file may cause denial of service (CVE-2024-7347) - Resolves: RHEL-85556 - nginx: Memory disclosure in the ngx_http_mp4_module (CVE-2022-41742) - Resolves:RHEL-91446 - nginx: Memory corruption in the ngx_http_mp4_module (CVE-2022-41741) [2:1.20.1-23] - Resolves: RHEL-6786 - SSL-errors 0A000126 / NS_NET_ERROR_PARTIAL_TRANSFER at nginx with reverse-proxy _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 9 released updated nginx with moderate severity fixes for data injection and DoS threats. Secure your systems now.. Oracle Linux 9, nginx security, moderate severity fixes. . LinuxSecurity.com Team

Calendar%202 Mar 25, 2026 Oracle
217

Oracle Linux 10 ELSA-2026-4705 ngnix Moderate Data Injection Risk

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-4705 http://linux.oracle.com/errata/ELSA-2026-4705.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: nginx-1.26.3-2.0.1.el10_1.x86_64.rpm nginx-all-modules-1.26.3-2.0.1.el10_1.noarch.rpm nginx-core-1.26.3-2.0.1.el10_1.x86_64.rpm nginx-filesystem-1.26.3-2.0.1.el10_1.noarch.rpm nginx-mod-devel-1.26.3-2.0.1.el10_1.x86_64.rpm nginx-mod-http-image-filter-1.26.3-2.0.1.el10_1.x86_64.rpm nginx-mod-http-perl-1.26.3-2.0.1.el10_1.x86_64.rpm nginx-mod-http-xslt-filter-1.26.3-2.0.1.el10_1.x86_64.rpm nginx-mod-mail-1.26.3-2.0.1.el10_1.x86_64.rpm nginx-mod-stream-1.26.3-2.0.1.el10_1.x86_64.rpm aarch64: nginx-1.26.3-2.0.1.el10_1.aarch64.rpm nginx-all-modules-1.26.3-2.0.1.el10_1.noarch.rpm nginx-core-1.26.3-2.0.1.el10_1.aarch64.rpm nginx-filesystem-1.26.3-2.0.1.el10_1.noarch.rpm nginx-mod-devel-1.26.3-2.0.1.el10_1.aarch64.rpm nginx-mod-http-image-filter-1.26.3-2.0.1.el10_1.aarch64.rpm nginx-mod-http-perl-1.26.3-2.0.1.el10_1.aarch64.rpm nginx-mod-http-xslt-filter-1.26.3-2.0.1.el10_1.aarch64.rpm nginx-mod-mail-1.26.3-2.0.1.el10_1.aarch64.rpm nginx-mod-stream-1.26.3-2.0.1.el10_1.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/nginx-1.26.3-2.0.1.el10_1.src.rpm Related CVEs: CVE-2026-1642 Description of changes: [2:1.26.3-2.0.1] - Reference oracle-indexhtml within Requires [Orabug: 33802044] [2:1.26.3-2] - CVE-2026-1642 nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 10 receives a security update for nginx to address a moderate data injection risk via TLS connections.. nginx security patch Oracle Linux data injection TLS connections. . LinuxSecurity.com Team

Calendar%202 Mar 17, 2026 Oracle
219

CentOS Stream 9 RLSA-2026-4823 nginx Critical flaw CVE-2026-1855

Moderate: nginx:1.26 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:4235", "synopsis": "Moderate: nginx:1.26 security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for module.nginx, nginx.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage. \n\nSecurity Fix(es):\n\n* nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections (CVE-2026-1642)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2436738", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2436738", "description": ""}], "cves": [{"name": "CVE-2026-1642", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-1642", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N", "cvss3BaseScore": "5.9", "cwe": "CWE-349"}], "references": [], "publishedAt": "2026-03-12T00:04:19.567917Z", "rpms": {"Rocky Linux 9": {"nvras": ["nginx-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.aarch64.rpm", "nginx-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.ppc64le.rpm", "nginx-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.s390x.rpm", "nginx-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.src.rpm", "nginx-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.x86_64.rpm", "nginx-all-modules-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.noarch.rpm", "nginx-core-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.aarch64.rpm", "nginx-core-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.ppc64le.rpm", "nginx-core-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.s390x.rpm","nginx-core-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.x86_64.rpm", "nginx-core-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.aarch64.rpm", "nginx-core-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.ppc64le.rpm", "nginx-core-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.s390x.rpm", "nginx-core-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.x86_64.rpm", "nginx-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.aarch64.rpm", "nginx-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.ppc64le.rpm", "nginx-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.s390x.rpm", "nginx-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.x86_64.rpm", "nginx-debugsource-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.aarch64.rpm", "nginx-debugsource-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.ppc64le.rpm", "nginx-debugsource-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.s390x.rpm", "nginx-debugsource-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.x86_64.rpm", "nginx-filesystem-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.noarch.rpm", "nginx-mod-devel-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.aarch64.rpm", "nginx-mod-devel-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.ppc64le.rpm", "nginx-mod-devel-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.s390x.rpm", "nginx-mod-devel-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.x86_64.rpm", "nginx-mod-http-image-filter-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.aarch64.rpm", "nginx-mod-http-image-filter-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.ppc64le.rpm", "nginx-mod-http-image-filter-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.s390x.rpm", "nginx-mod-http-image-filter-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.x86_64.rpm", "nginx-mod-http-image-filter-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.aarch64.rpm", "nginx-mod-http-image-filter-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.ppc64le.rpm", "nginx-mod-http-image-filter-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.s390x.rpm", "nginx-mod-http-image-filter-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.x86_64.rpm","nginx-mod-http-perl-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.aarch64.rpm", "nginx-mod-http-perl-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.ppc64le.rpm", "nginx-mod-http-perl-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.s390x.rpm", "nginx-mod-http-perl-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.x86_64.rpm", "nginx-mod-http-perl-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.aarch64.rpm", "nginx-mod-http-perl-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.ppc64le.rpm", "nginx-mod-http-perl-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.s390x.rpm", "nginx-mod-http-perl-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.x86_64.rpm", "nginx-mod-http-xslt-filter-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.aarch64.rpm", "nginx-mod-http-xslt-filter-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.ppc64le.rpm", "nginx-mod-http-xslt-filter-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.s390x.rpm", "nginx-mod-http-xslt-filter-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.x86_64.rpm", "nginx-mod-http-xslt-filter-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.aarch64.rpm", "nginx-mod-http-xslt-filter-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.ppc64le.rpm", "nginx-mod-http-xslt-filter-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.s390x.rpm", "nginx-mod-http-xslt-filter-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.x86_64.rpm", "nginx-mod-mail-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.aarch64.rpm", "nginx-mod-mail-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.ppc64le.rpm", "nginx-mod-mail-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.s390x.rpm", "nginx-mod-mail-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.x86_64.rpm", "nginx-mod-mail-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.aarch64.rpm", "nginx-mod-mail-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.ppc64le.rpm", "nginx-mod-mail-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.s390x.rpm", "nginx-mod-mail-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.x86_64.rpm", "nginx-mod-stream-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.aarch64.rpm","nginx-mod-stream-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.ppc64le.rpm", "nginx-mod-stream-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.s390x.rpm", "nginx-mod-stream-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.x86_64.rpm", "nginx-mod-stream-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.aarch64.rpm", "nginx-mod-stream-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.ppc64le.rpm", "nginx-mod-stream-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.s390x.rpm", "nginx-mod-stream-debuginfo-2:1.26.3-2.module+el9.7.0+40103+2443f6d1.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Stay updated on the Rocky Linux nginx security advisory with a moderate severity update against data injection risks via TLS.. nginx security update, Rocky Linux vulnerability, data injection threat. . LinuxSecurity.com Team

Calendar%202 Mar 12, 2026 Rocky Linux
217

Oracle Linux 9 ELSA-2026-3638 nginx 1.24 Moderate Data Injection DoS

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-3638 http://linux.oracle.com/errata/ELSA-2026-3638.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: nginx-1.24.0-5.0.1.module+el9.7.0+90821+c4114bda.1.x86_64.rpm nginx-all-modules-1.24.0-5.0.1.module+el9.7.0+90821+c4114bda.1.noarch.rpm nginx-core-1.24.0-5.0.1.module+el9.7.0+90821+c4114bda.1.x86_64.rpm nginx-filesystem-1.24.0-5.0.1.module+el9.7.0+90821+c4114bda.1.noarch.rpm nginx-mod-devel-1.24.0-5.0.1.module+el9.7.0+90821+c4114bda.1.x86_64.rpm nginx-mod-http-image-filter-1.24.0-5.0.1.module+el9.7.0+90821+c4114bda.1.x86_64.rpm nginx-mod-http-perl-1.24.0-5.0.1.module+el9.7.0+90821+c4114bda.1.x86_64.rpm nginx-mod-http-xslt-filter-1.24.0-5.0.1.module+el9.7.0+90821+c4114bda.1.x86_64.rpm nginx-mod-mail-1.24.0-5.0.1.module+el9.7.0+90821+c4114bda.1.x86_64.rpm nginx-mod-stream-1.24.0-5.0.1.module+el9.7.0+90821+c4114bda.1.x86_64.rpm aarch64: nginx-1.24.0-5.0.1.module+el9.7.0+90821+c4114bda.1.aarch64.rpm nginx-all-modules-1.24.0-5.0.1.module+el9.7.0+90821+c4114bda.1.noarch.rpm nginx-core-1.24.0-5.0.1.module+el9.7.0+90821+c4114bda.1.aarch64.rpm nginx-filesystem-1.24.0-5.0.1.module+el9.7.0+90821+c4114bda.1.noarch.rpm nginx-mod-devel-1.24.0-5.0.1.module+el9.7.0+90821+c4114bda.1.aarch64.rpm nginx-mod-http-image-filter-1.24.0-5.0.1.module+el9.7.0+90821+c4114bda.1.aarch64.rpm nginx-mod-http-perl-1.24.0-5.0.1.module+el9.7.0+90821+c4114bda.1.aarch64.rpm nginx-mod-http-xslt-filter-1.24.0-5.0.1.module+el9.7.0+90821+c4114bda.1.aarch64.rpm nginx-mod-mail-1.24.0-5.0.1.module+el9.7.0+90821+c4114bda.1.aarch64.rpm nginx-mod-stream-1.24.0-5.0.1.module+el9.7.0+90821+c4114bda.1.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/nginx-1.24.0-5.0.1.module+el9.7.0+90821+c4114bda.1.src.rpm Related CVEs: CVE-2026-1642 Description of changes: [1.24.0-5.1.0.1] - Reference oracle-indexhtml within Requires [Orabug: 33802044] -Remove Red Hat references [Orabug: 29498217] [1:1.24.0-5.1] - Resolves: RHEL-146526 - nginx:1.24/nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections (CVE-2026-1642) [1:1.24.0-5] - Resolves: RHEL-84480 - nginx:1.24/nginx: specially crafted MP4 file may cause denial of service (CVE-2024-7347) [1:1.24.0-4] - Resolves: RHEL-49350 - nginx worker processes memory leak [1:1.24.0-3] - Resolves: RHEL-40622 - openssl 3.2 ENGINE regression in nginx [1:1.24.0-2] - Resolves: RHEL-38498 - Nginx seg faults when proxy_ssl_certificate is set _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 9 has updated nginx packages addressing moderate security risks including data injection and DoS.. Oracle Linux security, nginx update, moderate severity, secure web server. . LinuxSecurity.com Team

Calendar%202 Mar 09, 2026 Oracle
219

Rocky Linux 9 nginx Security Issue Notification RLSB-2026-9785

Moderate: nginx:1.24 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:3638", "synopsis": "Moderate: nginx:1.24 security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for module.nginx, nginx.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage. \n\nSecurity Fix(es):\n\n* nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections (CVE-2026-1642)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2436738", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2436738", "description": ""}], "cves": [{"name": "CVE-2026-1642", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-1642", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N", "cvss3BaseScore": "5.9", "cwe": "CWE-349"}], "references": [], "publishedAt": "2026-03-05T09:09:17.804344Z", "rpms": {"Rocky Linux 9": {"nvras": ["nginx-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.aarch64.rpm", "nginx-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.ppc64le.rpm", "nginx-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.s390x.rpm", "nginx-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.src.rpm", "nginx-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.x86_64.rpm", "nginx-all-modules-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.noarch.rpm", "nginx-core-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.aarch64.rpm","nginx-core-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.ppc64le.rpm", "nginx-core-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.s390x.rpm", "nginx-core-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.x86_64.rpm", "nginx-core-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.aarch64.rpm", "nginx-core-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.ppc64le.rpm", "nginx-core-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.s390x.rpm", "nginx-core-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.x86_64.rpm", "nginx-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.aarch64.rpm", "nginx-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.ppc64le.rpm", "nginx-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.s390x.rpm", "nginx-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.x86_64.rpm", "nginx-debugsource-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.aarch64.rpm", "nginx-debugsource-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.ppc64le.rpm", "nginx-debugsource-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.s390x.rpm", "nginx-debugsource-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.x86_64.rpm", "nginx-filesystem-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.noarch.rpm", "nginx-mod-devel-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.aarch64.rpm", "nginx-mod-devel-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.ppc64le.rpm", "nginx-mod-devel-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.s390x.rpm", "nginx-mod-devel-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.x86_64.rpm", "nginx-mod-http-image-filter-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.aarch64.rpm", "nginx-mod-http-image-filter-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.ppc64le.rpm", "nginx-mod-http-image-filter-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.s390x.rpm","nginx-mod-http-image-filter-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.x86_64.rpm", "nginx-mod-http-image-filter-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.aarch64.rpm", "nginx-mod-http-image-filter-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.ppc64le.rpm", "nginx-mod-http-image-filter-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.s390x.rpm", "nginx-mod-http-image-filter-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.x86_64.rpm", "nginx-mod-http-perl-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.aarch64.rpm", "nginx-mod-http-perl-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.ppc64le.rpm", "nginx-mod-http-perl-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.s390x.rpm", "nginx-mod-http-perl-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.x86_64.rpm", "nginx-mod-http-perl-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.aarch64.rpm", "nginx-mod-http-perl-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.ppc64le.rpm", "nginx-mod-http-perl-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.s390x.rpm", "nginx-mod-http-perl-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.x86_64.rpm", "nginx-mod-http-xslt-filter-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.aarch64.rpm", "nginx-mod-http-xslt-filter-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.ppc64le.rpm", "nginx-mod-http-xslt-filter-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.s390x.rpm", "nginx-mod-http-xslt-filter-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.x86_64.rpm", "nginx-mod-http-xslt-filter-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.aarch64.rpm", "nginx-mod-http-xslt-filter-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.ppc64le.rpm", "nginx-mod-http-xslt-filter-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.s390x.rpm", "nginx-mod-http-xslt-filter-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.x86_64.rpm","nginx-mod-mail-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.aarch64.rpm", "nginx-mod-mail-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.ppc64le.rpm", "nginx-mod-mail-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.s390x.rpm", "nginx-mod-mail-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.x86_64.rpm", "nginx-mod-mail-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.aarch64.rpm", "nginx-mod-mail-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.ppc64le.rpm", "nginx-mod-mail-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.s390x.rpm", "nginx-mod-mail-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.x86_64.rpm", "nginx-mod-stream-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.aarch64.rpm", "nginx-mod-stream-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.ppc64le.rpm", "nginx-mod-stream-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.s390x.rpm", "nginx-mod-stream-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.x86_64.rpm", "nginx-mod-stream-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.aarch64.rpm", "nginx-mod-stream-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.ppc64le.rpm", "nginx-mod-stream-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.s390x.rpm", "nginx-mod-stream-debuginfo-1:1.24.0-5.module+el9.7.0+40088+99dbd8cd.1.rocky.0.1.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Rocky Linux 9 nginx moderate security update addresses data injection via TLS proxied connections. Learn more!. ninja update, Rocky Linux advisories, nginx tls security. . LinuxSecurity.com Team

Calendar%202 Mar 05, 2026 Rocky Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200