ELSA-2026-67308-0

ELSA-2026-67308-0 - nginx:1.24 security update

Type:SECURITY
Impact:MODERATE
Release Date:2026-09-15

Description


[1.24.0-7.5.0.1]
- Reference oracle-indexhtml within Requires [Orabug: 33802044]
- Remove Red Hat references [Orabug: 29498217]

[1:1.24.0-7.5]
- Resolves: RHEL-212508 - nginx:1.24/nginx: NGINX: Arbitrary code execution
via crafted HTTP requests (CVE-2026-42533)

[1:1.24.0-7.4]
- Resolves: RHEL-219310 - nginx: NGINX: Heap buffer over-read allows memory
modification or denial of service (CVE-2026-56434)
- Resolves: RHEL-217962 - nginx: NGINX: Memory disclosure and denial of service
in ngx_http_slice_module (CVE-2026-60005)

[1:1.24.0-7.3]
- Resolves: RHEL-191773 - nginx: 'HTTP/2 bomb' nginx fix breaks module ABI
causing crashes
- Resolves: RHEL-188413 - nginx: NGINX: Arbitrary code execution or.
Denial of Service via heap-based buffer overflow with crafted HTTP/2
headers (CVE-2026-42055)

[1:1.24.0-7.2]
- Resolves: RHEL-178681 - nginx:1.24/nginx: code execution and denial
of service (CVE-2026-9256)
- Resolves: RHEL-182554 - nginx:1.24/nginx: HTTP/2: Remote Denial of
Service via compression bomb and Slowloris-style attack

[1:1.24.0-7.1]
- Resolves: RHEL-176234 - nginx:1.24/nginx: NGINX: Arbitrary Code Execution
Vulnerability (CVE-2026-42945)

[1:1.24.0-7]
- Resolves: RHEL-157889 CVE-2026-32647 nginx:1.24/nginx: NGINX: Denial of
Service or Code Execution via specially crafted MP4 files
- Resolves: RHEL-159448 CVE-2026-27651 nginx:1.24/nginx: NGINX: Denial of
Service via undisclosed requests when ngx_mail_auth_http_module is enabled
- Resolves: RHEL-159561 CVE-2026-27654 nginx:1.24/nginx: NGINX: Denial of
Service or file modification via buffer overflow in ngx_http_dav_module
- Resolves: RHEL-159540 CVE-2026-27784 nginx:1.24/nginx: NGINX: Denial of
Service due to memory corruption via crafted MP4 file

[1:1.24.0-6]
- Resolves: RHEL-146529 - CVE-2026-1642 nginx: NGINX: Data injection via
man-in-the-middle attack on TLS proxied connections

[1:1.24.0-5]
- Resolves: RHEL-84480 - nginx:1.24/nginx: specially crafted MP4 file may cause
denial of service (CVE-2024-7347)


Related CVEs


CVE-2026-42533

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) nginx-1.24.0-7.0.1.module+el9.8.0+91033+c4928ca1.5.src.rpmc43c5570a7be44ba57ecc6a31476c87474e1c827df94b598722d44c2e2a965cc-ol9_aarch64_appstream
nginx-1.24.0-7.0.1.module+el9.8.0+91033+c4928ca1.5.aarch64.rpmb99a393ac2461484c432310d45ce234e32e71ca157990f6a2d6cdd876b91ae95-ol9_aarch64_appstream
nginx-all-modules-1.24.0-7.0.1.module+el9.8.0+91033+c4928ca1.5.noarch.rpm6031a89b4f4302e8d5170dfd96da9bbc6a0df95ebdcbdcf94055b11343d6be1a-ol9_aarch64_appstream
nginx-core-1.24.0-7.0.1.module+el9.8.0+91033+c4928ca1.5.aarch64.rpm51adc1bc43121687072045f560d7b1b7ea4832a1562694846e42ddc302f61ca7-ol9_aarch64_appstream
nginx-filesystem-1.24.0-7.0.1.module+el9.8.0+91033+c4928ca1.5.noarch.rpm29805e777ac2ad1746490a717e75045aadff0b0a30651eefd2a2d5222e2e3264-ol9_aarch64_appstream
nginx-mod-devel-1.24.0-7.0.1.module+el9.8.0+91033+c4928ca1.5.aarch64.rpm7e72b8852441bbdfc674a77ed58fdd872106b2832c073ec4569ab7ed8c18149a-ol9_aarch64_appstream
nginx-mod-http-image-filter-1.24.0-7.0.1.module+el9.8.0+91033+c4928ca1.5.aarch64.rpmd67bbc28858992121a30bd087d9fd1ffd0cc21cfac45fbf0d8b291473f41a860-ol9_aarch64_appstream
nginx-mod-http-perl-1.24.0-7.0.1.module+el9.8.0+91033+c4928ca1.5.aarch64.rpm35a7d2e0482a26fefc0d89731d6ce3b7f5062984b8364b08095c8114df8c64aa-ol9_aarch64_appstream
nginx-mod-http-xslt-filter-1.24.0-7.0.1.module+el9.8.0+91033+c4928ca1.5.aarch64.rpm27b41130725a02b69d67a498a165fc3acefc0a9d70c30f496ebc74bcefcc6cf0-ol9_aarch64_appstream
nginx-mod-mail-1.24.0-7.0.1.module+el9.8.0+91033+c4928ca1.5.aarch64.rpm852a3adca7b5844ecadab635a5e91fef20d8e92eacddccdb31b3599777ba8dbf-ol9_aarch64_appstream
nginx-mod-stream-1.24.0-7.0.1.module+el9.8.0+91033+c4928ca1.5.aarch64.rpm674b46fbc1f54e9f3dd56e9d0f3f7b9f4b39d179f05712c8eeed41098df86de5-ol9_aarch64_appstream
Oracle Linux 9 (x86_64) nginx-1.24.0-7.0.1.module+el9.8.0+91033+c4928ca1.5.src.rpmc43c5570a7be44ba57ecc6a31476c87474e1c827df94b598722d44c2e2a965cc-ol9_x86_64_appstream
nginx-1.24.0-7.0.1.module+el9.8.0+91033+c4928ca1.5.x86_64.rpmfcbaa595b6fcb99888051abaebe1e36ebe5e145d44bc19f4eec263d48c1a3a2f-ol9_x86_64_appstream
nginx-all-modules-1.24.0-7.0.1.module+el9.8.0+91033+c4928ca1.5.noarch.rpm6031a89b4f4302e8d5170dfd96da9bbc6a0df95ebdcbdcf94055b11343d6be1a-ol9_x86_64_appstream
nginx-core-1.24.0-7.0.1.module+el9.8.0+91033+c4928ca1.5.x86_64.rpmbd041df903ed51d9ba01e51b6000ac2ca6fa03055f0b6c0412191aaf10c45228-ol9_x86_64_appstream
nginx-filesystem-1.24.0-7.0.1.module+el9.8.0+91033+c4928ca1.5.noarch.rpm29805e777ac2ad1746490a717e75045aadff0b0a30651eefd2a2d5222e2e3264-ol9_x86_64_appstream
nginx-mod-devel-1.24.0-7.0.1.module+el9.8.0+91033+c4928ca1.5.x86_64.rpmf0860e3849000c8e90c4fe780b5122a0215dd59bddcc10dade4634b83ed74d31-ol9_x86_64_appstream
nginx-mod-http-image-filter-1.24.0-7.0.1.module+el9.8.0+91033+c4928ca1.5.x86_64.rpm24bf8ab153ff8d2ef3d8b0aa60adf63ff66664ec9765bed6328706267f778a37-ol9_x86_64_appstream
nginx-mod-http-perl-1.24.0-7.0.1.module+el9.8.0+91033+c4928ca1.5.x86_64.rpm0aa054eac2ab3c8956d330a8b9dd95a4d9ef8811070d461c369af401b0fdfd9e-ol9_x86_64_appstream
nginx-mod-http-xslt-filter-1.24.0-7.0.1.module+el9.8.0+91033+c4928ca1.5.x86_64.rpmbbb180bf567b17a6708c0366fa3ca6a63ce141f3e0fa22b01dab6932a28b201a-ol9_x86_64_appstream
nginx-mod-mail-1.24.0-7.0.1.module+el9.8.0+91033+c4928ca1.5.x86_64.rpmd22ee68392bed18dab235c2b10c24426dca0664078c82df5e3766b9413878094-ol9_x86_64_appstream
nginx-mod-stream-1.24.0-7.0.1.module+el9.8.0+91033+c4928ca1.5.x86_64.rpmc33a61f93011b8815d0094a39abe65929e6423858aebe5a02a003dbed70dda28-ol9_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete