ELSA-2026-67315-0

ELSA-2026-67315-0 - nginx:1.24 security update

Type:SECURITY
Impact:MODERATE
Release Date:2026-09-15

Description


[1.24.0-3.5.0.1]
- Remove Red Hat references [Orabug: 29498217]

[1:1.24.0-3.5]
- Resolves: RHEL-212457 - nginx:1.24/nginx: NGINX: Arbitrary code execution via
crafted HTTP requests (CVE-2026-42533)

[1:1.24.0-3.4]
- Resolves: RHEL-217957 - nginx:1.24/nginx: NGINX: Memory disclosure and
denial of service in ngx_http_slice_module (CVE-2026-60005)
- Resolves: RHEL-219309 - nginx:1.24/nginx: NGINX: Heap buffer over-read
allows memory modification or denial of service (CVE-2026-56434)

[1:1.24.0-3.3]
- Resolves: RHEL-191779 - nginx: 'HTTP/2 bomb' nginx fix breaks module ABI
causing crashes
- Resolves: RHEL-188406 - nginx: NGINX: Arbitrary code execution or.
Denial of Service via heap-based buffer overflow with crafted HTTP/2
headers (CVE-2026-42055)

[1:1.24.0-3.2]
- Resolves: RHEL-178676 - nginx:1.24/nginx: code execution and denial
of service (CVE-2026-9256)
- Resolves: RHEL-182543 - nginx: HTTP/2: Remote Denial of Service via
compression bomb and Slowloris-style attack

[1:1.24.0-3.1]
- Resolves: RHEL-176224 - nginx:1.24/nginx: NGINX: Arbitrary Code Execution
Vulnerability (CVE-2026-42945)

[1:1.24.0-3]
- Resolves: RHEL-157877 CVE-2026-32647 nginx:1.24/nginx: NGINX: Denial of
Service or Code Execution via specially crafted MP4 files
- Resolves: RHEL-159436 CVE-2026-27651 nginx:1.24/nginx: NGINX: Denial of
Service via undisclosed requests when ngx_mail_auth_http_module is enabled
- Resolves: RHEL-159549 CVE-2026-27654 nginx:1.24/nginx: NGINX: Denial of
Service or file modification via buffer overflow in ngx_http_dav_module
- Resolves: RHEL-159528 CVE-2026-27784 nginx:1.24/nginx: NGINX: Denial of
Service due to memory corruption via crafted MP4 file

[1:1.24.0-2]
- Resolves: RHEL-146517 - nginx:1.24/nginx: NGINX: Data injection via
man-in-the-middle attack on TLS proxied connections (CVE-2026-1642)

[1:1.24.0-1]
- Resolves: RHEL-14714 - add nginx:1.24 to RHEL 8.10

[1:1.22.1-2]
- Resolves: RHEL-12728 - nginx:1.22/nginx: HTTP/2: Multiple HTTP/2 enabled web
servers are vulnerable to a DDoS attack (Rapid Reset Attack)(CVE-2023-44487)


Related CVEs


CVE-2026-42533

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) nginx-1.24.0-3.0.1.module+el8.10.0+91032+1387c9a2.5.src.rpmdf5c9c7389574422ca3dd7012998115ac9d648d26d5be3e8c8802793899f9d1d-ol8_aarch64_appstream
nginx-1.24.0-3.0.1.module+el8.10.0+91032+1387c9a2.5.aarch64.rpma9e4ba187175fccd3a451ac0264440ae63664dbd893b0194015631271a0418f2-ol8_aarch64_appstream
nginx-all-modules-1.24.0-3.0.1.module+el8.10.0+91032+1387c9a2.5.noarch.rpm97396637aabb967fc3e62164052bed14b6aef67c03a5474ca0af18acab03e43d-ol8_aarch64_appstream
nginx-filesystem-1.24.0-3.0.1.module+el8.10.0+91032+1387c9a2.5.noarch.rpma39ee93bae0a624cc8b76ac2bb72f5542391cdf72261a2a527178f38906527ae-ol8_aarch64_appstream
nginx-mod-devel-1.24.0-3.0.1.module+el8.10.0+91032+1387c9a2.5.aarch64.rpm536a0182aec9f15d7206da9cb41a1f61449bccc44b86dac3e7e964cb7f421be9-ol8_aarch64_appstream
nginx-mod-http-image-filter-1.24.0-3.0.1.module+el8.10.0+91032+1387c9a2.5.aarch64.rpmd0165b6536eebb5e38f2dfdfed57e2d7667e16ed905840e8e131b95c08a12463-ol8_aarch64_appstream
nginx-mod-http-perl-1.24.0-3.0.1.module+el8.10.0+91032+1387c9a2.5.aarch64.rpmb719fae8fccf807f7635f358a03dda6d95bd488412d833a5b17fc33d9714d8de-ol8_aarch64_appstream
nginx-mod-http-xslt-filter-1.24.0-3.0.1.module+el8.10.0+91032+1387c9a2.5.aarch64.rpmec1f01eaab1ed3c3e758ec676264b4ee39b6dc7ff0620cbee7857c11a4814d02-ol8_aarch64_appstream
nginx-mod-mail-1.24.0-3.0.1.module+el8.10.0+91032+1387c9a2.5.aarch64.rpm2ba48d6da2862167c4d313cfad8d3b140a89a8c6e059db5ccb8faeb743f77609-ol8_aarch64_appstream
nginx-mod-stream-1.24.0-3.0.1.module+el8.10.0+91032+1387c9a2.5.aarch64.rpmd76726008a7138e8f5517aef72a5486b007505bc8cb7fbf7b8acd4e6c1840d27-ol8_aarch64_appstream
Oracle Linux 8 (x86_64) nginx-1.24.0-3.0.1.module+el8.10.0+91032+1387c9a2.5.src.rpmdf5c9c7389574422ca3dd7012998115ac9d648d26d5be3e8c8802793899f9d1d-ol8_x86_64_appstream
nginx-1.24.0-3.0.1.module+el8.10.0+91032+1387c9a2.5.x86_64.rpm5af4947fc9f0854bf5e1e5242e3600b9403b2152211916ef721e6c8e4ee55b7a-ol8_x86_64_appstream
nginx-all-modules-1.24.0-3.0.1.module+el8.10.0+91032+1387c9a2.5.noarch.rpm97396637aabb967fc3e62164052bed14b6aef67c03a5474ca0af18acab03e43d-ol8_x86_64_appstream
nginx-filesystem-1.24.0-3.0.1.module+el8.10.0+91032+1387c9a2.5.noarch.rpma39ee93bae0a624cc8b76ac2bb72f5542391cdf72261a2a527178f38906527ae-ol8_x86_64_appstream
nginx-mod-devel-1.24.0-3.0.1.module+el8.10.0+91032+1387c9a2.5.x86_64.rpmca655a6c3f8440ede3c9bedc53dbcda5ca46d4ca88fdfce0e2d30ac0b2195762-ol8_x86_64_appstream
nginx-mod-http-image-filter-1.24.0-3.0.1.module+el8.10.0+91032+1387c9a2.5.x86_64.rpmb221899c66cc43e052dfc4ad824e7b79ab78c6290a59a6be697d86dd2c681b6e-ol8_x86_64_appstream
nginx-mod-http-perl-1.24.0-3.0.1.module+el8.10.0+91032+1387c9a2.5.x86_64.rpm586e1daa730928a931a56c2c8951159f1b21eaa9cf620d00c56da8666f31be6c-ol8_x86_64_appstream
nginx-mod-http-xslt-filter-1.24.0-3.0.1.module+el8.10.0+91032+1387c9a2.5.x86_64.rpme0ce44a3eefec7671836c93c51b0a82a6312851a7ba14980bb4e8fda1e7c6eb0-ol8_x86_64_appstream
nginx-mod-mail-1.24.0-3.0.1.module+el8.10.0+91032+1387c9a2.5.x86_64.rpm50225a2eb7866a9fbb8e059b4ba22a7cf34fbfcbd0820340ed53d4be805bf873-ol8_x86_64_appstream
nginx-mod-stream-1.24.0-3.0.1.module+el8.10.0+91032+1387c9a2.5.x86_64.rpm372d088db2126bfa65f76019827756917490b34bf90e87cd5c2b8b3463db7b40-ol8_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete