elsa-2026-7343

oracle_linux
Description

[2:1.26.3-2.0.1.1] - Require oracle-indexhtml [2:1.26.3-6] - Resolves: RHEL-157887 - CVE-2026-32647 nginx:1.26/nginx: NGINX: Denial of Service or Code Execution via specially crafted MP4 files [2:1.26.3-5] - Resolves: RHEL-159446 - CVE-2026-27651 nginx:1.26/nginx: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled [2:1.26.3-4] - Resolves: RHEL-159538 - CVE-2026-27784 nginx:1.26/nginx: NGINX: Denial of Service due to memory corruption via crafted MP4 file [2:1.26.3-3] - Resolves: RHEL-159559 - CVE-2026-27654 nginx:1.26/nginx: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module [2:1.26.3-2] - nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections (CVE-2026-1642) [2:1.26.3-1] - New version 1.26.3 [2:1.26.2-4] - Use systemd-sysusers [2:1.26.2-3] - Fix PKCS-11 support [2:1.26.2-2] - Adjust QE files

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2026-27651",
    "CVE-2026-27654",
    "CVE-2026-27784",
    "CVE-2026-32647"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[2:1.26.3-2.0.1.1]\n- Require oracle-indexhtml\n\n[2:1.26.3-6]\n- Resolves: RHEL-157887 - CVE-2026-32647 nginx:1.26/nginx: NGINX: Denial of\n  Service or Code Execution via specially crafted MP4 files\n\n[2:1.26.3-5]\n- Resolves: RHEL-159446 - CVE-2026-27651 nginx:1.26/nginx: NGINX: Denial of\n  Service via undisclosed requests when ngx_mail_auth_http_module is\n  enabled\n\n[2:1.26.3-4]\n- Resolves: RHEL-159538 - CVE-2026-27784 nginx:1.26/nginx: NGINX: Denial of\n  Service due to memory corruption via crafted MP4 file\n\n[2:1.26.3-3]\n- Resolves: RHEL-159559 - CVE-2026-27654 nginx:1.26/nginx: NGINX: Denial of\n  Service or file modification via buffer overflow in ngx_http_dav_module\n\n[2:1.26.3-2]\n- nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied\n  connections (CVE-2026-1642)\n\n[2:1.26.3-1]\n- New version 1.26.3\n\n[2:1.26.2-4]\n- Use systemd-sysusers\n\n[2:1.26.2-3]\n- Fix PKCS-11 support\n\n[2:1.26.2-2]\n- Adjust QE files",
  "id": "ELSA-2026-7343",
  "ovalId": "oval:com.oracle.elsa:def:20267343",
  "source": "oracle_linux",
  "title": "ELSA-2026-7343:  nginx:1.26 security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-7343.html"
}
View JSON API Download JSON