ELSA-2026-59362

ELSA-2026-59362 - nginx security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-08-27

Description


[1.20.1-28.0.1.el9_8.5]
- Reference oracle-indexhtml within Requires [Orabug: 33802044]
- Remove Red Hat references [Orabug: 29498217]
- Update upstream references [Orabug: 36579090]

[2:1.20.1-28.5]
- Resolves: RHEL-219316 - nginx: NGINX: Heap buffer over-read allows memory
modification or denial of service (CVE-2026-56434)
- Resolves: RHEL-217969 - nginx: NGINX: Memory disclosure and denial of service
in ngx_http_slice_module (CVE-2026-60005)

[2:1.20.1-28.4]
- Resolves: RHEL-190800 - nginx: 'HTTP/2 bomb' nginx fix breaks module ABI
causing crashes
- Resolves: RHEL-188418 - nginx: NGINX: Arbitrary code execution or
Denial of Service via heap-based buffer overflow with crafted HTTP/2
headers (CVE-2026-42055)

[2:1.20.1-28.3]
- Resolves: RHEL-178684 - nginx: code execution and denial of
service (CVE-2026-9256)
- Resolves: RHEL-182553 - nginx: HTTP/2: Remote Denial of Service via
compression bomb and Slowloris-style attack

[2:1.20.1-28.2]
- Resolves: RHEL-176232 - nginx: NGINX: Arbitrary Code Execution
Vulnerability (CVE-2026-42945)

[2:1.20.1-28.1]
- RHEL-159560 CVE-2026-27654 nginx: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module
- RHEL-159539 CVE-2026-27784 nginx: NGINX: Denial of Service due to memory corruption via crafted MP4 file
- RHEL-159447 CVE-2026-27651 nginx: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled
- RHEL-157888 CVE-2026-32647 nginx: NGINX: Denial of Service or Code Execution via specially crafted MP4 files


Related CVEs


CVE-2026-56434
CVE-2026-60005

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) nginx-1.20.1-28.0.1.el9_8.5.src.rpm510342b767af79a3ef534c7f90a4f006866ddd5ffb2bb637873a012cbe1d0e07-ol9_aarch64_appstream
nginx-1.20.1-28.0.1.el9_8.5.src.rpm510342b767af79a3ef534c7f90a4f006866ddd5ffb2bb637873a012cbe1d0e07-ol9_aarch64_codeready_builder
nginx-1.20.1-28.0.1.el9_8.5.aarch64.rpm9e07c159e46342e60341904631a645c34149c745cadcc879ae2e1fcfe0b8c46b-ol9_aarch64_appstream
nginx-all-modules-1.20.1-28.0.1.el9_8.5.noarch.rpm353d8173a2b2b79eff1f108db87eab4ca96ba810d011fd436a5b4ecb0e650d68-ol9_aarch64_appstream
nginx-core-1.20.1-28.0.1.el9_8.5.aarch64.rpmdfc4201ed0974a69c2c97ea6d382068c43cc203e3512c98e53abb980fafd6c38-ol9_aarch64_appstream
nginx-filesystem-1.20.1-28.0.1.el9_8.5.noarch.rpmac25610edec841b7bd35cccb99d03129f26eb6cbaa663cae305487ecc6198728-ol9_aarch64_appstream
nginx-mod-devel-1.20.1-28.0.1.el9_8.5.aarch64.rpmfafd1c02a78286b8ad162a49bc5aa1a9e5e5b4ecb26ebc1cf1d6c699486b0d7e-ol9_aarch64_codeready_builder
nginx-mod-http-image-filter-1.20.1-28.0.1.el9_8.5.aarch64.rpm1408a16190f85a562cf8cb750f65a03811fe0c7dbbd8bf59079b65b02415a221-ol9_aarch64_appstream
nginx-mod-http-perl-1.20.1-28.0.1.el9_8.5.aarch64.rpmeb4aae2219e337ab88c0664efcf7baa6a66fe9d737465fe33a202ba5f9342e34-ol9_aarch64_appstream
nginx-mod-http-xslt-filter-1.20.1-28.0.1.el9_8.5.aarch64.rpm03f0e900a04eba910ddd7cc94180d4646f2ea0f60993056d85cab29a58104154-ol9_aarch64_appstream
nginx-mod-mail-1.20.1-28.0.1.el9_8.5.aarch64.rpmfb8ba7a2f1c80adc75fd2d05be769983b62ca94acfec5f6bdd57c57e73476f58-ol9_aarch64_appstream
nginx-mod-stream-1.20.1-28.0.1.el9_8.5.aarch64.rpma8e093dd4eb666179c1ce08548f4c7cedfe5855aae88a7bacb6d6d181567a2b3-ol9_aarch64_appstream
Oracle Linux 9 (x86_64) nginx-1.20.1-28.0.1.el9_8.5.src.rpm510342b767af79a3ef534c7f90a4f006866ddd5ffb2bb637873a012cbe1d0e07-ol9_x86_64_appstream
nginx-1.20.1-28.0.1.el9_8.5.src.rpm510342b767af79a3ef534c7f90a4f006866ddd5ffb2bb637873a012cbe1d0e07-ol9_x86_64_codeready_builder
nginx-1.20.1-28.0.1.el9_8.5.x86_64.rpm979e762e523e1c1a615a8dc826832bd9435e6fc0fc901650f28b51b5c2d88d3f-ol9_x86_64_appstream
nginx-all-modules-1.20.1-28.0.1.el9_8.5.noarch.rpm353d8173a2b2b79eff1f108db87eab4ca96ba810d011fd436a5b4ecb0e650d68-ol9_x86_64_appstream
nginx-core-1.20.1-28.0.1.el9_8.5.x86_64.rpm443dad548a9ed7918d72d9b7fbb9cdad737e3c22a05989f99b385ded4ce197f1-ol9_x86_64_appstream
nginx-filesystem-1.20.1-28.0.1.el9_8.5.noarch.rpmac25610edec841b7bd35cccb99d03129f26eb6cbaa663cae305487ecc6198728-ol9_x86_64_appstream
nginx-mod-devel-1.20.1-28.0.1.el9_8.5.x86_64.rpmf21c58cc7ef9d90dcdb3ee90604e58bb6a07249cba5a81402974b4ad53482546-ol9_x86_64_codeready_builder
nginx-mod-http-image-filter-1.20.1-28.0.1.el9_8.5.x86_64.rpmfc07b51011f4e985a86f3c74af664204f0d7dad5f169e5fde13c2cfaf330138a-ol9_x86_64_appstream
nginx-mod-http-perl-1.20.1-28.0.1.el9_8.5.x86_64.rpm1f3c38f9a56a6ef1f614a0c7b33c0419a38221e105ea02bd10e5a271cd1d7bfd-ol9_x86_64_appstream
nginx-mod-http-xslt-filter-1.20.1-28.0.1.el9_8.5.x86_64.rpmbd523daec0496006b50335d74c611cf816bb7ddcc084734efcb0b92d3e84da30-ol9_x86_64_appstream
nginx-mod-mail-1.20.1-28.0.1.el9_8.5.x86_64.rpm5c6455734fa4a82ac68ce4760eb3a6051c126faa91937a4e4fe2e9c37f3b7594-ol9_x86_64_appstream
nginx-mod-stream-1.20.1-28.0.1.el9_8.5.x86_64.rpm8731e8aef4907286cae85a426343edd204874af01d10717c345330239812216d-ol9_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete