ELSA-2026-66542-0

ELSA-2026-66542-0 - nginx security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-09-11

Description


[1.20.1-28.0.1.el9_8.6]
- Reference oracle-indexhtml within Requires [Orabug: 33802044]
- Remove Red Hat references [Orabug: 29498217]
- Update upstream references [Orabug: 36579090]

[2:1.20.1-28.6]
- Resolves: RHEL-212458 - nginx: NGINX: Arbitrary code execution via crafted
HTTP requests (CVE-2026-42533)

[2:1.20.1-28.5]
- Resolves: RHEL-219316 - nginx: NGINX: Heap buffer over-read allows memory
modification or denial of service (CVE-2026-56434)
- Resolves: RHEL-217969 - nginx: NGINX: Memory disclosure and denial of service
in ngx_http_slice_module (CVE-2026-60005)

[2:1.20.1-28.4]
- Resolves: RHEL-190800 - nginx: 'HTTP/2 bomb' nginx fix breaks module ABI
causing crashes
- Resolves: RHEL-188418 - nginx: NGINX: Arbitrary code execution or
Denial of Service via heap-based buffer overflow with crafted HTTP/2
headers (CVE-2026-42055)

[2:1.20.1-28.3]
- Resolves: RHEL-178684 - nginx: code execution and denial of
service (CVE-2026-9256)
- Resolves: RHEL-182553 - nginx: HTTP/2: Remote Denial of Service via
compression bomb and Slowloris-style attack

[2:1.20.1-28.2]
- Resolves: RHEL-176232 - nginx: NGINX: Arbitrary Code Execution
Vulnerability (CVE-2026-42945)

[2:1.20.1-28.1]
- RHEL-159560 CVE-2026-27654 nginx: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module
- RHEL-159539 CVE-2026-27784 nginx: NGINX: Denial of Service due to memory corruption via crafted MP4 file
- RHEL-159447 CVE-2026-27651 nginx: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled
- RHEL-157888 CVE-2026-32647 nginx: NGINX: Denial of Service or Code Execution via specially crafted MP4 files


Related CVEs


CVE-2026-42533

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) nginx-1.20.1-28.0.1.el9_8.6.src.rpm4104d1404fa75a74bab2bb1308719a967d3cb0d9ea30604c979617acc78196f0-ol9_aarch64_appstream
nginx-1.20.1-28.0.1.el9_8.6.src.rpm4104d1404fa75a74bab2bb1308719a967d3cb0d9ea30604c979617acc78196f0-ol9_aarch64_codeready_builder
nginx-1.20.1-28.0.1.el9_8.6.aarch64.rpm42a3db99bfa5bffc9d45aef7911a1853472033477cc5e922a5237b8409a34c51-ol9_aarch64_appstream
nginx-all-modules-1.20.1-28.0.1.el9_8.6.noarch.rpm03d88b46173d660e7df1f0ee03e541228e8c5af99e8e4ebaee253a30e15758ef-ol9_aarch64_appstream
nginx-core-1.20.1-28.0.1.el9_8.6.aarch64.rpmf8cace68703c52552ce21841ff8dd8642692e0817106cc3c5150e03a0943c5a0-ol9_aarch64_appstream
nginx-filesystem-1.20.1-28.0.1.el9_8.6.noarch.rpmb64ca6f0a3285298da8e38b58d65b2e183c954127da55d6960a4d76599eaa31e-ol9_aarch64_appstream
nginx-mod-devel-1.20.1-28.0.1.el9_8.6.aarch64.rpm74bb38290883ecada3dbc52da829c45fd7e128ded430de38592564d9b9c75c18-ol9_aarch64_codeready_builder
nginx-mod-http-image-filter-1.20.1-28.0.1.el9_8.6.aarch64.rpm729156ddf0c42f84166d6dab08968a87fb377d62c650ac966d958ffebc9947d3-ol9_aarch64_appstream
nginx-mod-http-perl-1.20.1-28.0.1.el9_8.6.aarch64.rpm6a5871ae2811be76cac5224e749b0dcc4600e7a289e0d4732f2140a4876c9063-ol9_aarch64_appstream
nginx-mod-http-xslt-filter-1.20.1-28.0.1.el9_8.6.aarch64.rpm3353aec5a56b8f89b0b6599f38945ac2ab2c763fda1c1c0d9fd757cfb06fac14-ol9_aarch64_appstream
nginx-mod-mail-1.20.1-28.0.1.el9_8.6.aarch64.rpmef9dc0c473150e4dc9cc91bdc749d429345fe59ab410e463810202ce8a7a5fe3-ol9_aarch64_appstream
nginx-mod-stream-1.20.1-28.0.1.el9_8.6.aarch64.rpm35eef71ec921a838bea893a6087f6305b03f5722612f7d09c8022653827361d6-ol9_aarch64_appstream
Oracle Linux 9 (x86_64) nginx-1.20.1-28.0.1.el9_8.6.src.rpm4104d1404fa75a74bab2bb1308719a967d3cb0d9ea30604c979617acc78196f0-ol9_x86_64_appstream
nginx-1.20.1-28.0.1.el9_8.6.src.rpm4104d1404fa75a74bab2bb1308719a967d3cb0d9ea30604c979617acc78196f0-ol9_x86_64_codeready_builder
nginx-1.20.1-28.0.1.el9_8.6.x86_64.rpm7bb1c3a726f641408adbfaaa180be4c69337fea6ec46ad8063215a5a61d89c5c-ol9_x86_64_appstream
nginx-all-modules-1.20.1-28.0.1.el9_8.6.noarch.rpm03d88b46173d660e7df1f0ee03e541228e8c5af99e8e4ebaee253a30e15758ef-ol9_x86_64_appstream
nginx-core-1.20.1-28.0.1.el9_8.6.x86_64.rpm2784696ada08afba18ccd58b36ceff54784f54c460ada390c3cc6758cdb61ff6-ol9_x86_64_appstream
nginx-filesystem-1.20.1-28.0.1.el9_8.6.noarch.rpmb64ca6f0a3285298da8e38b58d65b2e183c954127da55d6960a4d76599eaa31e-ol9_x86_64_appstream
nginx-mod-devel-1.20.1-28.0.1.el9_8.6.x86_64.rpmce4011b26d04e6e0b5b7ce6e004fd8254dc5894926fd86d0ac6daf2b6da698af-ol9_x86_64_codeready_builder
nginx-mod-http-image-filter-1.20.1-28.0.1.el9_8.6.x86_64.rpm0fe0346b5c8e473ab17ce016e973ddd1b8633c9677241667d14fa44bbb6cd415-ol9_x86_64_appstream
nginx-mod-http-perl-1.20.1-28.0.1.el9_8.6.x86_64.rpmc456d22ef2357da23f65f4441cf6ae69136cd18d4d4e773f424b5fcee8ffba88-ol9_x86_64_appstream
nginx-mod-http-xslt-filter-1.20.1-28.0.1.el9_8.6.x86_64.rpm172355a40d8276cf6e371e4af98bcc7a79c2faf2c6322bd8b9f746b509392e41-ol9_x86_64_appstream
nginx-mod-mail-1.20.1-28.0.1.el9_8.6.x86_64.rpmf3eeb766f688f16283c78f26f8eb7fac2aa4f11c9791f4d2275a82da6eb706e1-ol9_x86_64_appstream
nginx-mod-stream-1.20.1-28.0.1.el9_8.6.x86_64.rpm151b7d9cea87685ceeb246f760e9a0f53609516c04fa7f6d835dbf7039beef2d-ol9_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete