ELSA-2026-59216

ELSA-2026-59216 - nginx:1.24 security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-08-25

Description


[1.24.0-3.4.0.1]
- Remove Red Hat references [Orabug: 29498217]

[1:1.24.0-3.4]
- Resolves: RHEL-217957 - nginx:1.24/nginx: NGINX: Memory disclosure and
denial of service in ngx_http_slice_module (CVE-2026-60005)
- Resolves: RHEL-219309 - nginx:1.24/nginx: NGINX: Heap buffer over-read
allows memory modification or denial of service (CVE-2026-56434)

[1:1.24.0-3.3]
- Resolves: RHEL-191779 - nginx: 'HTTP/2 bomb' nginx fix breaks module ABI
causing crashes
- Resolves: RHEL-188406 - nginx: NGINX: Arbitrary code execution or.
Denial of Service via heap-based buffer overflow with crafted HTTP/2
headers (CVE-2026-42055)

[1:1.24.0-3.2]
- Resolves: RHEL-178676 - nginx:1.24/nginx: code execution and denial
of service (CVE-2026-9256)
- Resolves: RHEL-182543 - nginx: HTTP/2: Remote Denial of Service via
compression bomb and Slowloris-style attack

[1:1.24.0-3.1]
- Resolves: RHEL-176224 - nginx:1.24/nginx: NGINX: Arbitrary Code Execution
Vulnerability (CVE-2026-42945)

[1:1.24.0-3]
- Resolves: RHEL-157877 CVE-2026-32647 nginx:1.24/nginx: NGINX: Denial of
Service or Code Execution via specially crafted MP4 files
- Resolves: RHEL-159436 CVE-2026-27651 nginx:1.24/nginx: NGINX: Denial of
Service via undisclosed requests when ngx_mail_auth_http_module is enabled
- Resolves: RHEL-159549 CVE-2026-27654 nginx:1.24/nginx: NGINX: Denial of
Service or file modification via buffer overflow in ngx_http_dav_module
- Resolves: RHEL-159528 CVE-2026-27784 nginx:1.24/nginx: NGINX: Denial of
Service due to memory corruption via crafted MP4 file

[1:1.24.0-2]
- Resolves: RHEL-146517 - nginx:1.24/nginx: NGINX: Data injection via
man-in-the-middle attack on TLS proxied connections (CVE-2026-1642)

[1:1.24.0-1]
- Resolves: RHEL-14714 - add nginx:1.24 to RHEL 8.10

[1:1.22.1-2]
- Resolves: RHEL-12728 - nginx:1.22/nginx: HTTP/2: Multiple HTTP/2 enabled web
servers are vulnerable to a DDoS attack (Rapid Reset Attack)(CVE-2023-44487)

[1:1.22.1-1]
- Resolves: #2112345 - nginx:1.22 for RHEL 8
- add stream_geoip_module and stream_realip_module
- remove obsolete --with-ipv6


Related CVEs


CVE-2026-56434
CVE-2026-60005

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) nginx-1.24.0-3.0.1.module+el8.10.0+91001+0c279a1d.4.src.rpm6ecc5c72607f9e57d86892776787d1566de072fe1d4d34485cf30add8f73c935-ol8_aarch64_appstream
nginx-1.24.0-3.0.1.module+el8.10.0+91001+0c279a1d.4.aarch64.rpm786595694929ff0c8031d3a5733fe7132aa3a688d70235f6ff6692f405fa9ff8-ol8_aarch64_appstream
nginx-all-modules-1.24.0-3.0.1.module+el8.10.0+91001+0c279a1d.4.noarch.rpm4ec9fb5904ff37c2779bbc1322ca8acd8d6c3cc287421c33566599a8e3e6d839-ol8_aarch64_appstream
nginx-filesystem-1.24.0-3.0.1.module+el8.10.0+91001+0c279a1d.4.noarch.rpm5d70c792eb2d095a7ca12359801ef9a801e01959b706c2f21515bbeba77d4082-ol8_aarch64_appstream
nginx-mod-devel-1.24.0-3.0.1.module+el8.10.0+91001+0c279a1d.4.aarch64.rpm413491515d0e120e2a29be354d7dec89c0607a6c6a8028b98ea412bf07b88ca8-ol8_aarch64_appstream
nginx-mod-http-image-filter-1.24.0-3.0.1.module+el8.10.0+91001+0c279a1d.4.aarch64.rpm11a963001629274aa410af1d581d2855c63c5263eae44988a2eb9e24f7ce2f7a-ol8_aarch64_appstream
nginx-mod-http-perl-1.24.0-3.0.1.module+el8.10.0+91001+0c279a1d.4.aarch64.rpmb197a5e0bc302ded52f07e3f09d49b8cb5792c1dc5776f20811768ce08b052d5-ol8_aarch64_appstream
nginx-mod-http-xslt-filter-1.24.0-3.0.1.module+el8.10.0+91001+0c279a1d.4.aarch64.rpm444c53340da24c4d501ae7f8ba45bb1c46da63c29eafd6ce339215ebf0cfcd49-ol8_aarch64_appstream
nginx-mod-mail-1.24.0-3.0.1.module+el8.10.0+91001+0c279a1d.4.aarch64.rpm9f61ead631f60641dd998461370c1e60fde80fdb93869cbd1f203b23ca423e19-ol8_aarch64_appstream
nginx-mod-stream-1.24.0-3.0.1.module+el8.10.0+91001+0c279a1d.4.aarch64.rpm46a941b6b17d26f81de9c0137a636100a48631dd4de9d4b24e1e90110b37a2dd-ol8_aarch64_appstream
Oracle Linux 8 (x86_64) nginx-1.24.0-3.0.1.module+el8.10.0+91001+0c279a1d.4.src.rpm6ecc5c72607f9e57d86892776787d1566de072fe1d4d34485cf30add8f73c935-ol8_x86_64_appstream
nginx-1.24.0-3.0.1.module+el8.10.0+91001+0c279a1d.4.x86_64.rpm92aec029405524714d241948381ce7cdf4b4be347b96ea554fad99279424d96a-ol8_x86_64_appstream
nginx-all-modules-1.24.0-3.0.1.module+el8.10.0+91001+0c279a1d.4.noarch.rpm4ec9fb5904ff37c2779bbc1322ca8acd8d6c3cc287421c33566599a8e3e6d839-ol8_x86_64_appstream
nginx-filesystem-1.24.0-3.0.1.module+el8.10.0+91001+0c279a1d.4.noarch.rpm5d70c792eb2d095a7ca12359801ef9a801e01959b706c2f21515bbeba77d4082-ol8_x86_64_appstream
nginx-mod-devel-1.24.0-3.0.1.module+el8.10.0+91001+0c279a1d.4.x86_64.rpmc3738988886d966c21fb4fbde0a00b655b6c93563894fc8760fecde5a87f5750-ol8_x86_64_appstream
nginx-mod-http-image-filter-1.24.0-3.0.1.module+el8.10.0+91001+0c279a1d.4.x86_64.rpm1536bdc3b84da5c7c03bc66420d681700b6637c5234cfbedd0f3e659405daa9f-ol8_x86_64_appstream
nginx-mod-http-perl-1.24.0-3.0.1.module+el8.10.0+91001+0c279a1d.4.x86_64.rpm0616116a8f6b83eef7d990c9afd5e399392975d63fca897b6b2f581862d61c1c-ol8_x86_64_appstream
nginx-mod-http-xslt-filter-1.24.0-3.0.1.module+el8.10.0+91001+0c279a1d.4.x86_64.rpm9d9cd63444e3398fa41f613b04c551991960b8914731b968d8b29add5ac57a39-ol8_x86_64_appstream
nginx-mod-mail-1.24.0-3.0.1.module+el8.10.0+91001+0c279a1d.4.x86_64.rpmcc0e1ba289b8e3fec1c0421edbc493e0a22eb6a535f7ee8656406cde7ca87db0-ol8_x86_64_appstream
nginx-mod-stream-1.24.0-3.0.1.module+el8.10.0+91001+0c279a1d.4.x86_64.rpmc4578bc5850c8e9e57194871f1e52ea5f1acbc2bd48f9e32f09c712db3766086-ol8_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete