-------------------------------------------------------------------------
Debian LTS Advisory DLA-4784-1                [email protected]
https://www.debian.org/lts/security/          Carlos Henrique Lima Melara
September 17, 2026                            https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package        : nginx
Version        : 1.22.1-9+deb12u10
CVE ID         : CVE-2026-42533 CVE-2026-56434 CVE-2026-60005

Multiple vulnerabilities were discovered in nginx, a high-performance web
and reverse proxy server, which may result in denial of service, memory
disclosure or potentially the execution of arbitrary code.

CVE-2026-42533

    A heap buffer overflow was discovered in the nginx script engine. It
    can be triggered when a map directive performs regular expression
    matching and a string expression references captures modified by the
    map, or when non-cacheable variables change between the script length
    pass and the script copy pass.

CVE-2026-56434

    Duplicate finalization of an HTTP subrequest can result in a
    use-after-free. The issue is observable in configurations using
    server-side includes together with proxy_pass and proxy_buffering
    disabled, when an upstream response causes the same subrequest to be
    posted twice.

CVE-2026-60005

    ngx_http_regex_exec() could replace the captures array without
    clearing r->ncaptures when the new regular expression did not match.
    A subsequent unnamed capture could then access uninitialised memory,
    resulting in memory disclosure.

For Debian 12 bookworm, these problems have been fixed in version
1.22.1-9+deb12u10.

We recommend that you upgrade your nginx packages.

For the detailed security status of nginx please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/nginx

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Attachment: signature.asc
Description: PGP signature

Reply via email to