MGASA-2026-0301

Source
https://advisories.mageia.org/MGASA-2026-0301.html
Import Source
https://advisories.mageia.org/MGASA-2026-0301.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2026-0301
Upstream
  • CVE-2026-42533
  • CVE-2026-56434
  • CVE-2026-60005
Published
2026-07-27T22:45:13Z
Modified
2026-07-27T23:00:05.899586278Z
Summary
Updated nginx packages fix security vulnerabilities
Details

CVE-2026-42533: Heap buffer overflow might occur in a worker process when using the map directive with regex matching if the map variable was included in a string expression after a capture affected by this map; a similar issue might happen when using a non-cacheable variable in a string expression. Thanks to Mufeed VH of Winfunc Research and Maxim Dounin. . CVE-2026-60005: Uninitialized memory access might occur when using unnamed regex captures with the "slice" directive or background cache update, which could result in worker process memory disclosure or worker process termination. . CVE-2026-56434: Use-after-free might occur when processing a specially crafted proxied backend response with the ngxhttpssifiltermodule. Thanks to P4P3R-HAK.

References
Credits

Affected packages

Mageia:10 / nginx

Package

Name
nginx
Purl
pkg:rpm/mageia/nginx?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.30.4-1.mga10

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0301.json"

Mageia:9 / nginx

Package

Name
nginx
Purl
pkg:rpm/mageia/nginx?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.30.4-1.mga9

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0301.json"