Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 586
Alerts This Week
Warning Icon 1 586

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 274 articles for you...
172

Ubuntu 26.04 nginx Critical Denial of Service Vuln 8563-1

Several security issues were fixed in nginx.. ========================================================================== Ubuntu Security Notice USN-8563-1 July 20, 2026 nginx vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in nginx. Software Description: - nginx: small, powerful, scalable web/proxy server Details: It was discovered that nginx incorrectly handled certain map directives using regex matching and capture variables. A remote attacker could use this issue to cause nginx to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-42533) It was discovered that nginx had a use-after-free vulnerability in the ngx_http_ssi_module module when configured with Server-Side Includes, proxy_pass, and proxy buffering disabled directives. An attacker able to intercept traffic and control responses from an upstream server could possibly use this issue to cause nginx to crash, resulting in a denial of service. (CVE-2026-56434) It was discovered that nginx incorrectly handled certain requests in the ngx_http_slice_module module. A remote attacker could possibly use this issue to obtain sensitive information or cause nginx to crash, resulting in a denial of service. (CVE-2026-60005) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS nginx 1.28.3-2ubuntu1.7 nginx-core 1.28.3-2ubuntu1.7 nginx-extras 1.28.3-2ubuntu1.7 nginx-full 1.28.3-2ubuntu1.7 nginx-light 1.28.3-2ubuntu1.7 Ubuntu 24.04 LTS nginx 1.24.0-2ubuntu7.14 nginx-core 1.24.0-2ubuntu7.14 nginx-extras 1.24.0-2ubuntu7.14 nginx-full 1.24.0-2ubuntu7.14 nginx-light 1.24.0-2ubuntu7.14 Ubuntu 22.04 LTS nginx 1.18.0-6ubuntu14.17 nginx-core 1.18.0-6ubuntu14.17 nginx-extras 1.18.0-6ubuntu14.17 nginx-full 1.18.0-6ubuntu14.17 nginx-light 1.18.0-6ubuntu14.17 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8563-1 CVE-2026-42533, CVE-2026-56434, CVE-2026-60005 Package Information: https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.7 https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.14 https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.17 . Several security issues in nginx fixed for Ubuntu 26.04, 24.04 and 22.04 LTS impact functionality and security.. nginx vulnerabilities, Ubuntu security, denial of service, critical security update, arbitrary code execution. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 20, 2026 Critical Ubuntu
202

openSUSE Nginx New Moderate Update Advisory Released 2026-11295-1

An update that solves 3 vulnerabilities can now be installed.. # nginx-1.31.3-1.1 on GA media Announcement ID: openSUSE-SU-2026:11295-1 Rating: moderate Cross-References: * CVE-2026-42533 * CVE-2026-56434 * CVE-2026-60005 CVSS scores: * CVE-2026-42533 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42533 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56434 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-56434 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-60005 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-60005 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves 3 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the nginx-1.31.3-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * nginx 1.31.3-1.1 * nginx-source 1.31.3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42533.html * https://www.suse.com/security/cve/CVE-2026-56434.html * https://www.suse.com/security/cve/CVE-2026-60005.html . An update for openSUSE addresses three security issues in nginx-1.31.3-1.1 with moderate severity ratings.. openSUSE security update, nginx issues, security vulnerabilities, software patching. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jul 18, 2026 moderate OpenSUSE
217

Oracle Nginx Important Buffer Overflow Fix Advisory ELSA-2026-36331

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-36331 http://linux.oracle.com/errata/ELSA-2026-36331.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: nginx-1.20.1-28.0.1.el9_8.4.x86_64.rpm nginx-all-modules-1.20.1-28.0.1.el9_8.4.noarch.rpm nginx-core-1.20.1-28.0.1.el9_8.4.x86_64.rpm nginx-filesystem-1.20.1-28.0.1.el9_8.4.noarch.rpm nginx-mod-devel-1.20.1-28.0.1.el9_8.4.x86_64.rpm nginx-mod-http-image-filter-1.20.1-28.0.1.el9_8.4.x86_64.rpm nginx-mod-http-perl-1.20.1-28.0.1.el9_8.4.x86_64.rpm nginx-mod-http-xslt-filter-1.20.1-28.0.1.el9_8.4.x86_64.rpm nginx-mod-mail-1.20.1-28.0.1.el9_8.4.x86_64.rpm nginx-mod-stream-1.20.1-28.0.1.el9_8.4.x86_64.rpm aarch64: nginx-1.20.1-28.0.1.el9_8.4.aarch64.rpm nginx-all-modules-1.20.1-28.0.1.el9_8.4.noarch.rpm nginx-core-1.20.1-28.0.1.el9_8.4.aarch64.rpm nginx-filesystem-1.20.1-28.0.1.el9_8.4.noarch.rpm nginx-mod-devel-1.20.1-28.0.1.el9_8.4.aarch64.rpm nginx-mod-http-image-filter-1.20.1-28.0.1.el9_8.4.aarch64.rpm nginx-mod-http-perl-1.20.1-28.0.1.el9_8.4.aarch64.rpm nginx-mod-http-xslt-filter-1.20.1-28.0.1.el9_8.4.aarch64.rpm nginx-mod-mail-1.20.1-28.0.1.el9_8.4.aarch64.rpm nginx-mod-stream-1.20.1-28.0.1.el9_8.4.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/nginx-1.20.1-28.0.1.el9_8.4.src.rpm Related CVEs: CVE-2026-42055 Description of changes: [1.20.1-28.0.1.el9_8.4] - Reference oracle-indexhtml within Requires [Orabug: 33802044] - Remove Red Hat references [Orabug: 29498217] - Update upstream references [Orabug: 36579090] [2:1.20.1-28.4] - Resolves: RHEL-190800 - nginx: "HTTP/2 bomb" nginx fix breaks module ABI causing crashes - Resolves: RHEL-188418 - nginx: NGINX: Arbitrary code execution or Denial of Service via heap-based buffer overflow with crafted HTTP/2 headers (CVE-2026-42055) [2:1.20.1-28.3] - Resolves: RHEL-178684 - nginx: code execution and denial of service(CVE-2026-9256) - Resolves: RHEL-182553 - nginx: HTTP/2: Remote Denial of Service via compression bomb and Slowloris-style attack [2:1.20.1-28.2] - Resolves: RHEL-176232 - nginx: NGINX: Arbitrary Code Execution Vulnerability (CVE-2026-42945) [2:1.20.1-28.1] - RHEL-159560 CVE-2026-27654 nginx: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module - RHEL-159539 CVE-2026-27784 nginx: NGINX: Denial of Service due to memory corruption via crafted MP4 file - RHEL-159447 CVE-2026-27651 nginx: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled - RHEL-157888 CVE-2026-32647 nginx: NGINX: Denial of Service or Code Execution via specially crafted MP4 files _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 9 updates address security issues in nginx, including fixes for buffer overflow and denial of service vulnerabilities.. Oracle Linux 9, Nginx Bug Fix, Important Advisory, Buffer Overflow Fix, Security Updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 14, 2026 Important Oracle
217

Oracle Linux 9 nginx Important Denial of Service Fix ELSA-2026-36639

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-36639 http://linux.oracle.com/errata/ELSA-2026-36639.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: nginx-1.26.3-9.0.1.module+el9.8.0+90950+a1e882cd.2.x86_64.rpm nginx-all-modules-1.26.3-9.0.1.module+el9.8.0+90950+a1e882cd.2.noarch.rpm nginx-core-1.26.3-9.0.1.module+el9.8.0+90950+a1e882cd.2.x86_64.rpm nginx-filesystem-1.26.3-9.0.1.module+el9.8.0+90950+a1e882cd.2.noarch.rpm nginx-mod-devel-1.26.3-9.0.1.module+el9.8.0+90950+a1e882cd.2.x86_64.rpm nginx-mod-http-image-filter-1.26.3-9.0.1.module+el9.8.0+90950+a1e882cd.2.x86_64.rpm nginx-mod-http-perl-1.26.3-9.0.1.module+el9.8.0+90950+a1e882cd.2.x86_64.rpm nginx-mod-http-xslt-filter-1.26.3-9.0.1.module+el9.8.0+90950+a1e882cd.2.x86_64.rpm nginx-mod-mail-1.26.3-9.0.1.module+el9.8.0+90950+a1e882cd.2.x86_64.rpm nginx-mod-stream-1.26.3-9.0.1.module+el9.8.0+90950+a1e882cd.2.x86_64.rpm aarch64: nginx-1.26.3-9.0.1.module+el9.8.0+90950+a1e882cd.2.aarch64.rpm nginx-all-modules-1.26.3-9.0.1.module+el9.8.0+90950+a1e882cd.2.noarch.rpm nginx-core-1.26.3-9.0.1.module+el9.8.0+90950+a1e882cd.2.aarch64.rpm nginx-filesystem-1.26.3-9.0.1.module+el9.8.0+90950+a1e882cd.2.noarch.rpm nginx-mod-devel-1.26.3-9.0.1.module+el9.8.0+90950+a1e882cd.2.aarch64.rpm nginx-mod-http-image-filter-1.26.3-9.0.1.module+el9.8.0+90950+a1e882cd.2.aarch64.rpm nginx-mod-http-perl-1.26.3-9.0.1.module+el9.8.0+90950+a1e882cd.2.aarch64.rpm nginx-mod-http-xslt-filter-1.26.3-9.0.1.module+el9.8.0+90950+a1e882cd.2.aarch64.rpm nginx-mod-mail-1.26.3-9.0.1.module+el9.8.0+90950+a1e882cd.2.aarch64.rpm nginx-mod-stream-1.26.3-9.0.1.module+el9.8.0+90950+a1e882cd.2.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/nginx-1.26.3-9.0.1.module+el9.8.0+90950+a1e882cd.2.src.rpm Related CVEs: CVE-2026-42055 Description of changes: [1.26.3-9.0.1.2] - Require oracle-indexhtml [2:1.26.3-12] - Resolves:RHEL-191774 - nginx: "HTTP/2 bomb" nginx fix breaks module ABI causing crashes [2:1.26.3-11] - nginx:1.26/nginx: HTTP/2: Remote Denial of Service via compression bomb and Slowloris-style attack [2:1.26.3-10] - nginx: code execution and denial of service (CVE-2026-9256) [2:1.26.3-9] - Resolves: RHEL-176218 - nginx:1.26/nginx: NGINX: Arbitrary Code Execution Vulnerability (CVE-2026-42945) [2:1.26.3-8] - CVE-2026-32647 nginx:1.26/nginx: NGINX: Denial of Service or Code Execution via specially crafted MP4 files [2:1.26.3-7] - CVE-2026-27651 nginx:1.26/nginx: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled [2:1.26.3-6] - CVE-2026-27784 nginx:1.26/nginx: NGINX: Denial of Service due to memory corruption via crafted MP4 file [2:1.26.3-5] - CVE-2026-27654 nginx:1.26/nginx: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module [2:1.26.3-4] - CVE-2026-1642 nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Advisory ELSA-2026-36639 addresses important issues with nginx including denial of service fixes.. Oracle Linux, nginx, security advisory, denial of service, bug fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 13, 2026 Important Oracle
217

Oracle Linux 9 Nginx Important Buffer Overflow Advisory ELSA-2026-36618

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-36618 http://linux.oracle.com/errata/ELSA-2026-36618.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: nginx-1.24.0-7.0.1.module+el9.8.0+90951+a848b39d.3.x86_64.rpm nginx-all-modules-1.24.0-7.0.1.module+el9.8.0+90951+a848b39d.3.noarch.rpm nginx-core-1.24.0-7.0.1.module+el9.8.0+90951+a848b39d.3.x86_64.rpm nginx-filesystem-1.24.0-7.0.1.module+el9.8.0+90951+a848b39d.3.noarch.rpm nginx-mod-devel-1.24.0-7.0.1.module+el9.8.0+90951+a848b39d.3.x86_64.rpm nginx-mod-http-image-filter-1.24.0-7.0.1.module+el9.8.0+90951+a848b39d.3.x86_64.rpm nginx-mod-http-perl-1.24.0-7.0.1.module+el9.8.0+90951+a848b39d.3.x86_64.rpm nginx-mod-http-xslt-filter-1.24.0-7.0.1.module+el9.8.0+90951+a848b39d.3.x86_64.rpm nginx-mod-mail-1.24.0-7.0.1.module+el9.8.0+90951+a848b39d.3.x86_64.rpm nginx-mod-stream-1.24.0-7.0.1.module+el9.8.0+90951+a848b39d.3.x86_64.rpm aarch64: nginx-1.24.0-7.0.1.module+el9.8.0+90951+a848b39d.3.aarch64.rpm nginx-all-modules-1.24.0-7.0.1.module+el9.8.0+90951+a848b39d.3.noarch.rpm nginx-core-1.24.0-7.0.1.module+el9.8.0+90951+a848b39d.3.aarch64.rpm nginx-filesystem-1.24.0-7.0.1.module+el9.8.0+90951+a848b39d.3.noarch.rpm nginx-mod-devel-1.24.0-7.0.1.module+el9.8.0+90951+a848b39d.3.aarch64.rpm nginx-mod-http-image-filter-1.24.0-7.0.1.module+el9.8.0+90951+a848b39d.3.aarch64.rpm nginx-mod-http-perl-1.24.0-7.0.1.module+el9.8.0+90951+a848b39d.3.aarch64.rpm nginx-mod-http-xslt-filter-1.24.0-7.0.1.module+el9.8.0+90951+a848b39d.3.aarch64.rpm nginx-mod-mail-1.24.0-7.0.1.module+el9.8.0+90951+a848b39d.3.aarch64.rpm nginx-mod-stream-1.24.0-7.0.1.module+el9.8.0+90951+a848b39d.3.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/nginx-1.24.0-7.0.1.module+el9.8.0+90951+a848b39d.3.src.rpm Related CVEs: CVE-2026-42055 Description of changes: [1.24.0-7.0.1.3] - Reference oracle-indexhtml within Requires [Orabug:33802044] - Remove Red Hat references [Orabug: 29498217] [1:1.24.0-7.3] - Resolves: RHEL-191773 - nginx: "HTTP/2 bomb" nginx fix breaks module ABI causing crashes - Resolves: RHEL-188413 - nginx: NGINX: Arbitrary code execution or. Denial of Service via heap-based buffer overflow with crafted HTTP/2 headers (CVE-2026-42055) [1:1.24.0-7.2] - Resolves: RHEL-178681 - nginx:1.24/nginx: code execution and denial of service (CVE-2026-9256) - Resolves: RHEL-182554 - nginx:1.24/nginx: HTTP/2: Remote Denial of Service via compression bomb and Slowloris-style attack [1:1.24.0-7.1] - Resolves: RHEL-176234 - nginx:1.24/nginx: NGINX: Arbitrary Code Execution Vulnerability (CVE-2026-42945) [1:1.24.0-7] - Resolves: RHEL-157889 CVE-2026-32647 nginx:1.24/nginx: NGINX: Denial of Service or Code Execution via specially crafted MP4 files - Resolves: RHEL-159448 CVE-2026-27651 nginx:1.24/nginx: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled - Resolves: RHEL-159561 CVE-2026-27654 nginx:1.24/nginx: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module - Resolves: RHEL-159540 CVE-2026-27784 nginx:1.24/nginx: NGINX: Denial of Service due to memory corruption via crafted MP4 file [1:1.24.0-6] - Resolves: RHEL-146529 - CVE-2026-1642 nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections [1:1.24.0-5] - Resolves: RHEL-84480 - nginx:1.24/nginx: specially crafted MP4 file may cause denial of service (CVE-2024-7347) [1:1.24.0-4] - Resolves: RHEL-49350 - nginx worker processes memory leak _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Newly released Oracle Linux Security Advisory ELSA-2026-36618 for nginx involves crucial bug fixes and enhancements.. Oracle Linux Advisory, Nginx Bug Fixes, Important Patch, Buffer Overflow Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 13, 2026 Important Oracle
217

Oracle Linux 9 nginx Important Code Exec DoS ELSA-2026-28973

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-28973 http://linux.oracle.com/errata/ELSA-2026-28973.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: nginx-1.20.1-28.0.1.el9_8.3.x86_64.rpm nginx-all-modules-1.20.1-28.0.1.el9_8.3.noarch.rpm nginx-core-1.20.1-28.0.1.el9_8.3.x86_64.rpm nginx-filesystem-1.20.1-28.0.1.el9_8.3.noarch.rpm nginx-mod-devel-1.20.1-28.0.1.el9_8.3.x86_64.rpm nginx-mod-http-image-filter-1.20.1-28.0.1.el9_8.3.x86_64.rpm nginx-mod-http-perl-1.20.1-28.0.1.el9_8.3.x86_64.rpm nginx-mod-http-xslt-filter-1.20.1-28.0.1.el9_8.3.x86_64.rpm nginx-mod-mail-1.20.1-28.0.1.el9_8.3.x86_64.rpm nginx-mod-stream-1.20.1-28.0.1.el9_8.3.x86_64.rpm aarch64: nginx-1.20.1-28.0.1.el9_8.3.aarch64.rpm nginx-all-modules-1.20.1-28.0.1.el9_8.3.noarch.rpm nginx-core-1.20.1-28.0.1.el9_8.3.aarch64.rpm nginx-filesystem-1.20.1-28.0.1.el9_8.3.noarch.rpm nginx-mod-devel-1.20.1-28.0.1.el9_8.3.aarch64.rpm nginx-mod-http-image-filter-1.20.1-28.0.1.el9_8.3.aarch64.rpm nginx-mod-http-perl-1.20.1-28.0.1.el9_8.3.aarch64.rpm nginx-mod-http-xslt-filter-1.20.1-28.0.1.el9_8.3.aarch64.rpm nginx-mod-mail-1.20.1-28.0.1.el9_8.3.aarch64.rpm nginx-mod-stream-1.20.1-28.0.1.el9_8.3.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/nginx-1.20.1-28.0.1.el9_8.3.src.rpm Related CVEs: CVE-2026-9256 Description of changes: [2:1.20.1-28.0.1.el9_8.3] - Reference oracle-indexhtml within Requires [Orabug: 33802044] - Remove Red Hat references [Orabug: 29498217] - Update upstream references [Orabug: 36579090] [2:1.20.1-28.3] - Resolves: RHEL-178684 - nginx: code execution and denial of service (CVE-2026-9256) - Resolves: RHEL-182553 - nginx: HTTP/2: Remote Denial of Service via compression bomb and Slowloris-style attack [2:1.20.1-28.2] - Resolves: RHEL-176232 - nginx: NGINX: Arbitrary Code Execution Vulnerability (CVE-2026-42945) [2:1.20.1-28.1] - RHEL-159560CVE-2026-27654 nginx: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module - RHEL-159539 CVE-2026-27784 nginx: NGINX: Denial of Service due to memory corruption via crafted MP4 file - RHEL-159447 CVE-2026-27651 nginx: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled - RHEL-157888 CVE-2026-32647 nginx: NGINX: Denial of Service or Code Execution via specially crafted MP4 files _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Updates released for Oracle Linux 9 include important fixes for nginx, addressing multiple issues and vulnerabilities.. Oracle Linux 9, nginx security, code execution, denial of service, linux updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 06, 2026 Important Oracle
197

Debian LTS nginx Critical Remote Code Exec Denial of Service DLA-4667-1

Multiple vulnerabilities were discoverd in Nginx, a high-performance web and reverse proxy server, which could result in remote code execution, denial of service or memory disclosure. CVE-2026-42055 NGINX Open Source has a vulnerability in the ngx_http_proxy_v2_module and. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4667-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Carlos Henrique Lima Melara July 03, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : nginx Version : 1.22.1-9+deb12u9 CVE ID : CVE-2026-42055 CVE-2026-48142 Debian Bug : 1140359 1140361 Multiple vulnerabilities were discoverd in Nginx, a high-performance web and reverse proxy server, which could result in remote code execution, denial of service or memory disclosure. CVE-2026-42055 NGINX Open Source has a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. CVE-2026-48142 NGINX Open Source has a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote,unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. For Debian 12 bookworm, these problems have been fixed in version 1.22.1-9+deb12u9. We recommend that you upgrade your nginx packages. For the detailed security status of nginx please refer to its security tracker page at: https://security-tracker.debian.org/tracker/nginx Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ensure your systems are secure by upgrading to the fixed Nginx version addressing critical vulnerabilities.. Nginx security update, Debian LTS advisory, RCE vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 03, 2026 Critical Debian LTS
172

Ubuntu 20.04 LTS nginx Important Resource Consumption Issue USN-8398-4

nginx could be made to consume excessive resources if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-8398-4 July 02, 2026 nginx vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: nginx could be made to consume excessive resources if it received specially crafted network traffic. Software Description: - nginx: small, powerful, scalable web/proxy server Details: USN-8398-3 fixed a vulnerability in nginx. This update provides the corresponding fix for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that nginx incorrectly handled certain cookie headers in the HTTP/2 implementation. A remote attacker could possibly use this issue to cause nginx to consume excessive resources, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS nginx 1.18.0-0ubuntu1.7+esm3 Available with Ubuntu Pro nginx-common 1.18.0-0ubuntu1.7+esm3 Available with Ubuntu Pro nginx-core 1.18.0-0ubuntu1.7+esm3 Available with Ubuntu Pro nginx-extras 1.18.0-0ubuntu1.7+esm3 Available with Ubuntu Pro nginx-full 1.18.0-0ubuntu1.7+esm3 Available with Ubuntu Pro nginx-light 1.18.0-0ubuntu1.7+esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS nginx 1.14.0-0ubuntu1.11+esm4 Available with Ubuntu Pro nginx-core 1.14.0-0ubuntu1.11+esm4 Available with Ubuntu Pro nginx-extras 1.14.0-0ubuntu1.11+esm4 Available with Ubuntu Pro nginx-full 1.14.0-0ubuntu1.11+esm4 Available with Ubuntu Pro nginx-light 1.14.0-0ubuntu1.11+esm4 Available with Ubuntu Pro Ubuntu 16.04 LTS nginx 1.10.3-0ubuntu0.16.04.5+esm9 Available with Ubuntu Pro nginx-common 1.10.3-0ubuntu0.16.04.5+esm9 Available with Ubuntu Pro nginx-core 1.10.3-0ubuntu0.16.04.5+esm9 Available with Ubuntu Pro nginx-extras 1.10.3-0ubuntu0.16.04.5+esm9 Available with Ubuntu Pro nginx-full 1.10.3-0ubuntu0.16.04.5+esm9 Available with Ubuntu Pro nginx-light 1.10.3-0ubuntu0.16.04.5+esm9 Available with Ubuntu Pro Ubuntu 14.04 LTS nginx 1.4.6-1ubuntu3.9+esm8 Available with Ubuntu Pro nginx-common 1.4.6-1ubuntu3.9+esm8 Available with Ubuntu Pro nginx-core 1.4.6-1ubuntu3.9+esm8 Available with Ubuntu Pro nginx-extras 1.4.6-1ubuntu3.9+esm8 Available with Ubuntu Pro nginx-full 1.4.6-1ubuntu3.9+esm8 Available with Ubuntu Pro nginx-light 1.4.6-1ubuntu3.9+esm8 Available with Ubuntu Pro In general, a standard system update will make all the necessarychanges. References: https://ubuntu.com/security/notices/USN-8398-4 https://ubuntu.com/security/notices/USN-8398-3 https://ubuntu.com/security/notices/USN-8398-2 https://ubuntu.com/security/notices/USN-8398-1 CVE-2026-49975 . Update your Ubuntu system as nginx has a fix for a critical resource consumption issue. Protect against DoS attacks.. nginx resource fix, Ubuntu security update, denial of service mitigation, web server security issues, nginx vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 02, 2026 Important Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200