elsa-2026-36618

oracle_linux
Description

[1.24.0-7.0.1.3] - Reference oracle-indexhtml within Requires [Orabug: 33802044] - Remove Red Hat references [Orabug: 29498217] [1:1.24.0-7.3] - Resolves: RHEL-191773 - nginx: 'HTTP/2 bomb' nginx fix breaks module ABI causing crashes - Resolves: RHEL-188413 - nginx: NGINX: Arbitrary code execution or. Denial of Service via heap-based buffer overflow with crafted HTTP/2 headers (CVE-2026-42055) [1:1.24.0-7.2] - Resolves: RHEL-178681 - nginx:1.24/nginx: code execution and denial of service (CVE-2026-9256) - Resolves: RHEL-182554 - nginx:1.24/nginx: HTTP/2: Remote Denial of Service via compression bomb and Slowloris-style attack [1:1.24.0-7.1] - Resolves: RHEL-176234 - nginx:1.24/nginx: NGINX: Arbitrary Code Execution Vulnerability (CVE-2026-42945) [1:1.24.0-7] - Resolves: RHEL-157889 CVE-2026-32647 nginx:1.24/nginx: NGINX: Denial of Service or Code Execution via specially crafted MP4 files - Resolves: RHEL-159448 CVE-2026-27651 nginx:1.24/nginx: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled - Resolves: RHEL-159561 CVE-2026-27654 nginx:1.24/nginx: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module - Resolves: RHEL-159540 CVE-2026-27784 nginx:1.24/nginx: NGINX: Denial of Service due to memory corruption via crafted MP4 file [1:1.24.0-6] - Resolves: RHEL-146529 - CVE-2026-1642 nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections [1:1.24.0-5] - Resolves: RHEL-84480 - nginx:1.24/nginx: specially crafted MP4 file may cause denial of service (CVE-2024-7347) [1:1.24.0-4] - Resolves: RHEL-49350 - nginx worker processes memory leak

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2026-42055"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[1.24.0-7.0.1.3]\n- Reference oracle-indexhtml within Requires [Orabug: 33802044]\n- Remove Red Hat references [Orabug: 29498217]\n\n[1:1.24.0-7.3]\n- Resolves: RHEL-191773 - nginx: 'HTTP/2 bomb' nginx fix breaks module ABI\n  causing crashes\n- Resolves: RHEL-188413 - nginx: NGINX: Arbitrary code execution or.\n  Denial of Service via heap-based buffer overflow with crafted HTTP/2\n  headers (CVE-2026-42055)\n\n[1:1.24.0-7.2]\n- Resolves: RHEL-178681 - nginx:1.24/nginx: code execution and denial\n  of service (CVE-2026-9256)\n- Resolves: RHEL-182554 - nginx:1.24/nginx: HTTP/2: Remote Denial of\n  Service via compression bomb and Slowloris-style attack\n\n[1:1.24.0-7.1]\n- Resolves: RHEL-176234 - nginx:1.24/nginx: NGINX: Arbitrary Code Execution\n  Vulnerability (CVE-2026-42945)\n\n[1:1.24.0-7]\n- Resolves: RHEL-157889 CVE-2026-32647 nginx:1.24/nginx: NGINX: Denial of\n  Service or Code Execution via specially crafted MP4 files\n- Resolves: RHEL-159448 CVE-2026-27651 nginx:1.24/nginx: NGINX: Denial of\n  Service via undisclosed requests when ngx_mail_auth_http_module is enabled\n- Resolves: RHEL-159561 CVE-2026-27654 nginx:1.24/nginx: NGINX: Denial of\n  Service or file modification via buffer overflow in ngx_http_dav_module\n- Resolves: RHEL-159540 CVE-2026-27784 nginx:1.24/nginx: NGINX: Denial of\n  Service due to memory corruption via crafted MP4 file\n\n[1:1.24.0-6]\n- Resolves: RHEL-146529 -  CVE-2026-1642 nginx: NGINX: Data injection via\n  man-in-the-middle attack on TLS proxied connections\n\n[1:1.24.0-5]\n- Resolves: RHEL-84480 - nginx:1.24/nginx: specially crafted MP4 file may cause\n  denial of service (CVE-2024-7347)\n\n[1:1.24.0-4]\n- Resolves: RHEL-49350 - nginx worker processes memory leak",
  "id": "ELSA-2026-36618",
  "ovalId": "oval:com.oracle.elsa:def:202636618",
  "source": "oracle_linux",
  "title": "ELSA-2026-36618:  nginx:1.24 security, bug fix, and enhancement update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-36618.html"
}
View JSON API Download JSON