USN-7285-1: nginx vulnerability
It was discovered that nginx incorrectly handled when multiple server blocks are configured to share the same IP address and port. An attacker could use this issue to use session resumption to bypass client certificate authentication requirements on these servers. This issue only affected Ubuntu 24.10. A buffer overflow and a null pointer deref was fixed in nginx rtmp module (#LP 1977718). This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7285-1?
The severity of USN-7285-1 is considered high due to the potential for session resumption to bypass client certificate authentication.
How do I fix USN-7285-1?
To fix USN-7285-1, upgrade to nginx version 1.26.0-2ubuntu3.2 or higher.
Which versions of nginx are affected by USN-7285-1?
Versions of nginx prior to 1.26.0-2ubuntu3.2 on Ubuntu 24.10 and earlier are affected by USN-7285-1.
How can an attacker exploit the vulnerability in USN-7285-1?
An attacker can exploit the vulnerability in USN-7285-1 by using session resumption to bypass client certificate authentication on affected servers.
Is the vulnerability in USN-7285-1 remote or local?
The vulnerability described in USN-7285-1 is considered a remote vulnerability as it can be exploited over the network.