ELSA-2026-59490

ELSA-2026-59490 - nginx:1.24 security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-08-31

Description


[1.24.0-7.0.1.4]
- Reference oracle-indexhtml within Requires [Orabug: 33802044]
- Remove Red Hat references [Orabug: 29498217]

[1:1.24.0-7.4]
- Resolves: RHEL-219310 - nginx: NGINX: Heap buffer over-read allows memory
modification or denial of service (CVE-2026-56434)
- Resolves: RHEL-217962 - nginx: NGINX: Memory disclosure and denial of service
in ngx_http_slice_module (CVE-2026-60005)

[1:1.24.0-7.3]
- Resolves: RHEL-191773 - nginx: 'HTTP/2 bomb' nginx fix breaks module ABI
causing crashes
- Resolves: RHEL-188413 - nginx: NGINX: Arbitrary code execution or.
Denial of Service via heap-based buffer overflow with crafted HTTP/2
headers (CVE-2026-42055)

[1:1.24.0-7.2]
- Resolves: RHEL-178681 - nginx:1.24/nginx: code execution and denial
of service (CVE-2026-9256)
- Resolves: RHEL-182554 - nginx:1.24/nginx: HTTP/2: Remote Denial of
Service via compression bomb and Slowloris-style attack

[1:1.24.0-7.1]
- Resolves: RHEL-176234 - nginx:1.24/nginx: NGINX: Arbitrary Code Execution
Vulnerability (CVE-2026-42945)

[1:1.24.0-7]
- Resolves: RHEL-157889 CVE-2026-32647 nginx:1.24/nginx: NGINX: Denial of
Service or Code Execution via specially crafted MP4 files
- Resolves: RHEL-159448 CVE-2026-27651 nginx:1.24/nginx: NGINX: Denial of
Service via undisclosed requests when ngx_mail_auth_http_module is enabled
- Resolves: RHEL-159561 CVE-2026-27654 nginx:1.24/nginx: NGINX: Denial of
Service or file modification via buffer overflow in ngx_http_dav_module
- Resolves: RHEL-159540 CVE-2026-27784 nginx:1.24/nginx: NGINX: Denial of
Service due to memory corruption via crafted MP4 file

[1:1.24.0-6]
- Resolves: RHEL-146529 - CVE-2026-1642 nginx: NGINX: Data injection via
man-in-the-middle attack on TLS proxied connections

[1:1.24.0-5]
- Resolves: RHEL-84480 - nginx:1.24/nginx: specially crafted MP4 file may cause
denial of service (CVE-2024-7347)


Related CVEs


CVE-2026-56434
CVE-2026-60005

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) nginx-1.24.0-7.0.1.module+el9.8.0+91007+069d25a3.4.src.rpm26adf72a4a55b28aa4cc33c05667a1680f491c2a9414ab019d4b0baa2e73a96b-ol9_aarch64_appstream
nginx-1.24.0-7.0.1.module+el9.8.0+91007+069d25a3.4.aarch64.rpmbca7df15da57b3780923a0276b322d3bca165145a2200f7988da4b45a55b07a6-ol9_aarch64_appstream
nginx-all-modules-1.24.0-7.0.1.module+el9.8.0+91007+069d25a3.4.noarch.rpm00d65aa2fc1faf0a2e615031ae42010ff13158d5a5cf88d66f261bfb16decd6b-ol9_aarch64_appstream
nginx-core-1.24.0-7.0.1.module+el9.8.0+91007+069d25a3.4.aarch64.rpm10c24c02b861e9b0cfb8eb746bae07ed22afac91f12d8964d4aecab287e78457-ol9_aarch64_appstream
nginx-filesystem-1.24.0-7.0.1.module+el9.8.0+91007+069d25a3.4.noarch.rpm4513c26dbbdb3b9c4e1c81c546f7bcbeeccff7656f15407868b3b9915926fa91-ol9_aarch64_appstream
nginx-mod-devel-1.24.0-7.0.1.module+el9.8.0+91007+069d25a3.4.aarch64.rpm2fe0492e3aaec7ee7e92d51a6b232b96d6c5117b88149e4557dab97e16640e4f-ol9_aarch64_appstream
nginx-mod-http-image-filter-1.24.0-7.0.1.module+el9.8.0+91007+069d25a3.4.aarch64.rpmd4a554049f37edcc2f060213aa15e7e1d87a1a0c46ed83063a0d8d4722c85794-ol9_aarch64_appstream
nginx-mod-http-perl-1.24.0-7.0.1.module+el9.8.0+91007+069d25a3.4.aarch64.rpm42753701408e3a7ff5787485e89a63b6e62fbce1df97b6ee38c4198c3acbd9ce-ol9_aarch64_appstream
nginx-mod-http-xslt-filter-1.24.0-7.0.1.module+el9.8.0+91007+069d25a3.4.aarch64.rpmc606331047208792866076955e811fc6c1063194e907c33ec08f8079f00e734a-ol9_aarch64_appstream
nginx-mod-mail-1.24.0-7.0.1.module+el9.8.0+91007+069d25a3.4.aarch64.rpmf2904d81d7bcb5fca91761dd294be0eb12edee7c99cafa7887561a89d61a7357-ol9_aarch64_appstream
nginx-mod-stream-1.24.0-7.0.1.module+el9.8.0+91007+069d25a3.4.aarch64.rpm023f538caefb00e69d123a7d70d878595ca30f06efefc394c50823bc7b2449cf-ol9_aarch64_appstream
Oracle Linux 9 (x86_64) nginx-1.24.0-7.0.1.module+el9.8.0+91007+069d25a3.4.src.rpm26adf72a4a55b28aa4cc33c05667a1680f491c2a9414ab019d4b0baa2e73a96b-ol9_x86_64_appstream
nginx-1.24.0-7.0.1.module+el9.8.0+91007+069d25a3.4.x86_64.rpm96cd93c56b45d02cd7d81da479a8f0af7c89b34d15a308d2eb4532f76992b175-ol9_x86_64_appstream
nginx-all-modules-1.24.0-7.0.1.module+el9.8.0+91007+069d25a3.4.noarch.rpm00d65aa2fc1faf0a2e615031ae42010ff13158d5a5cf88d66f261bfb16decd6b-ol9_x86_64_appstream
nginx-core-1.24.0-7.0.1.module+el9.8.0+91007+069d25a3.4.x86_64.rpmef50138a6e1d988200e3ab4ff0ed19ee9fd5969a61b4085c743c6a7f0eb010de-ol9_x86_64_appstream
nginx-filesystem-1.24.0-7.0.1.module+el9.8.0+91007+069d25a3.4.noarch.rpm4513c26dbbdb3b9c4e1c81c546f7bcbeeccff7656f15407868b3b9915926fa91-ol9_x86_64_appstream
nginx-mod-devel-1.24.0-7.0.1.module+el9.8.0+91007+069d25a3.4.x86_64.rpm4d17591b8be3a59a0fbff1c9ff48c1fbac48ba82f7cf520208cc94dad076c9bc-ol9_x86_64_appstream
nginx-mod-http-image-filter-1.24.0-7.0.1.module+el9.8.0+91007+069d25a3.4.x86_64.rpm58203c18f23de3ce3496223cd1791583e7de28cdb71b67431d21cbc47d571e9f-ol9_x86_64_appstream
nginx-mod-http-perl-1.24.0-7.0.1.module+el9.8.0+91007+069d25a3.4.x86_64.rpmb1e912f2281a453916a9455c8fb2aa97c7306aaa389e8dba9d458c4a2eaf8dcc-ol9_x86_64_appstream
nginx-mod-http-xslt-filter-1.24.0-7.0.1.module+el9.8.0+91007+069d25a3.4.x86_64.rpm07303c1ae0c18189d5cb78e6f77639b2414b1241d86e037c884cd06937612dd6-ol9_x86_64_appstream
nginx-mod-mail-1.24.0-7.0.1.module+el9.8.0+91007+069d25a3.4.x86_64.rpmedfc7ec17863ed5f17d7a57f5470da445bc53e71153b725bdddfd415fb495ba0-ol9_x86_64_appstream
nginx-mod-stream-1.24.0-7.0.1.module+el9.8.0+91007+069d25a3.4.x86_64.rpm8fadb1fbd2216b30643a95857dea2141bfb92ddb4ed5f4011c2c9f29d270d163-ol9_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete