RHSA-2026:59362: Important: nginx security update
nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage. Security Fix(es): nginx: NGINX: Heap buffer over-read allows memory modification or denial of service (CVE-2026-56434) nginx: NGINX: Memory disclosure and denial of service in ngxhttpslicemodule (CVE-2026-60005) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/nginxto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5 - Upgrade
Upgrade
redhat/nginx-all-modulesto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5 - Upgrade
Upgrade
redhat/nginx-coreto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5 - Upgrade
Upgrade
redhat/nginx-core-debuginfoto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5 - Upgrade
Upgrade
redhat/nginx-debuginfoto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5 - Upgrade
Upgrade
redhat/nginx-debugsourceto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5 - Upgrade
Upgrade
redhat/nginx-filesystemto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5 - Upgrade
Upgrade
redhat/nginx-mod-http-image-filterto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5 - Upgrade
Upgrade
redhat/nginx-mod-http-image-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5 - Upgrade
Upgrade
redhat/nginx-mod-http-perlto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5 - Upgrade
Upgrade
redhat/nginx-mod-http-perl-debuginfoto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5 - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filterto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5 - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5 - Upgrade
Upgrade
redhat/nginx-mod-mailto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5 - Upgrade
Upgrade
redhat/nginx-mod-mail-debuginfoto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5 - Upgrade
Upgrade
redhat/nginx-mod-streamto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5 - Upgrade
Upgrade
redhat/nginx-mod-stream-debuginfoto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5 - Upgrade
Upgrade
redhat/nginxto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5.aa - Upgrade
Upgrade
redhat/nginx-coreto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5.aa - Upgrade
Upgrade
redhat/nginx-core-debuginfoto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5.aa - Upgrade
Upgrade
redhat/nginx-debuginfoto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5.aa - Upgrade
Upgrade
redhat/nginx-debugsourceto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5.aa - Upgrade
Upgrade
redhat/nginx-mod-http-image-filterto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5.aa - Upgrade
Upgrade
redhat/nginx-mod-http-image-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5.aa - Upgrade
Upgrade
redhat/nginx-mod-http-perlto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5.aa - Upgrade
Upgrade
redhat/nginx-mod-http-perl-debuginfoto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5.aa - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filterto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5.aa - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5.aa - Upgrade
Upgrade
redhat/nginx-mod-mailto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5.aa - Upgrade
Upgrade
redhat/nginx-mod-mail-debuginfoto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5.aa - Upgrade
Upgrade
redhat/nginx-mod-streamto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5.aa - Upgrade
Upgrade
redhat/nginx-mod-stream-debuginfoto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5.aa - Upgrade
Upgrade
redhat/nginx-mod-develto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5 - Upgrade
Upgrade
redhat/nginx-mod-develto a version that resolves this vulnerability.Fixed in 1.20.1-28.el9_8.5.aa - Compensating control
Apply the nginx security update described in the advisory referenced by Red Hat (access.redhat.com/articles/11258), which includes fixes for NGINX heap buffer over-read (CVE-2026-56434) and ngx_http_slice_module memory disclosure/DoS (CVE-2026-60005).