Package "nginx-full"
| Name: |
nginx-full
|
Description: |
nginx web/proxy server (standard version with 3rd parties)
|
| Latest version: |
1.24.0-2ubuntu7.16 |
| Release: |
noble (24.04) |
| Level: |
security |
| Repository: |
universe |
| Head package: |
nginx |
| Homepage: |
https://nginx.org |
Links
Download "nginx-full"
Other versions of "nginx-full" in Noble
Changelog
|
nginx (1.24.0-2ubuntu7.13) noble-security; urgency=medium
* SECURITY UPDATE: heap overflow via large headers
- debian/patches/CVE-2026-42055.patch: limit header length for HTTP/2 and
gRPC in src/http/modules/ngx_http_grpc_module.c.
- CVE-2026-42055
* SECURITY UPDATE: heap overread in ngx_http_charset_module
- debian/patches/CVE-2026-48142.patch: Charset: fixed another rare buffer
overread in recode_from_utf8() in
src/http/modules/ngx_http_charset_filter_module.c.
- CVE-2026-48142
-- Marc Deslauriers <email address hidden> Fri, 19 Jun 2026 09:52:54 -0400
|
| Source diff to previous version |
| CVE-2026-42055 |
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists whe |
| CVE-2026-48142 |
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location blo |
|
|
nginx (1.24.0-2ubuntu7.12) noble-security; urgency=medium
* SECURITY UPDATE: HTTP/2 Bomb denial of service
- debian/patches/CVE-2026-49975.patch: updated to patch from Debian's
1.26.3-3+deb13u6 package which was modified to not break ABI by
storing the information in a new ngx_http_header_count_module module.
Thanks to Miao Wang and Jan MojžÃÅ¡ for the modified patch!
- CVE-2026-49975
-- Marc Deslauriers <email address hidden> Wed, 10 Jun 2026 16:12:11 -0400
|
| CVE-2026-49975 |
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. T |
|
About
-
Send Feedback to @ubuntu_updates