Red Hat Product Errata RHSA-2026:36618 - Security Advisory Issued: 2026-07-08 Updated: 2026-07-08 RHSA-2026:36618 - Security Advisory Overview Updated Packages Synopsis Important: nginx:1.24 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the nginx:1.24 module is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage. Security Fix(es): nginx: NGINX: Arbitrary code execution or Denial of Service via heap-based buffer overflow with crafted HTTP/2 headers (CVE-2026-42055) Bug Fix(es) and Enhancement(s): nginx:1.24/nginx: "HTTP/2 bomb" nginx fix breaks module ABI causing crashes [rhel-9.8.z] (JIRA:RHEL-191773) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2489866 - CVE-2026-42055 nginx: NGINX: Arbitrary code execution or Denial of Service via heap-based buffer overflow with crafted HTTP/2 headers CVEs CVE-2026-42055 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM nginx-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.src.rpm SHA-256: ab8b32a9dd7a5611281c557630784ebacd52506e360384c5e502f3f02dc02481 x86_64 nginx-all-modules-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.noarch.rpm SHA-256: db3bff4d79ca48254d71d87db95062732526639f88241e6f87e2adf3f70e4994 nginx-filesystem-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.noarch.rpm SHA-256: a9e55364f10808f8f2e7ce723a6c808027b446e3d3b27c16e63499b89605c34e nginx-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: 5c677318f82fd42972a2e0230483e49875f4783ac30740058051214ddef07144 nginx-all-modules-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.noarch.rpm SHA-256: db3bff4d79ca48254d71d87db95062732526639f88241e6f87e2adf3f70e4994 nginx-core-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: 943f2f8f2201a123419b0508bd3d32ab71fc7ec074671d9093d7402536f682e3 nginx-core-debuginfo-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: e247a4467220b2275770c1745b6337e8b832ce566e98a5d42385322c3f3f0a56 nginx-debuginfo-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: 9a25be853076563d2cb964606940510a04708d29668fcbcd88d9ad9b01ce620d nginx-debugsource-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: d3231be62efab92683496f11f8e903b92ece2204c57959763c338e01872f43e9 nginx-filesystem-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.noarch.rpm SHA-256: a9e55364f10808f8f2e7ce723a6c808027b446e3d3b27c16e63499b89605c34e nginx-mod-devel-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: bd127683d0e2cea047532df6ec3bb8739cf100909ae3324d7d3088097f86fee6 nginx-mod-http-image-filter-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: 393973bca6909e8dba8dd1c536ebd000573703d0abf6511c5bd593370deb9831 nginx-mod-http-image-filter-debuginfo-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: 95b132cf2b07cb24157e60ea53a71b675fc6d9eba7d24364861d2d3712509e49 nginx-mod-http-perl-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: 399284bdeeacbdfe91b8b709e4fd67841f8210ac39c3d447daabfed2e50d9e07 nginx-mod-http-perl-debuginfo-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: 38b79e0766d0708ccacc945eb17a0bf8e7da64938b147bfb9f7d8d5d463fc059 nginx-mod-http-xslt-filter-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: 8a24a969beaf321c41039c56d51020860c9da558fb5408c116a274ae77401b79 nginx-mod-http-xslt-filter-debuginfo-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: 6d5586393fffe1c5ab849e31af9c5b414ae23b1fd51f855f61893903683a5333 nginx-mod-mail-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: 18f70229e059a9a6f6b61d5430f8158007926e362110824227d2ba83532120c4 nginx-mod-mail-debuginfo-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: 404e1451b8e200b05f7bda9f2a683612d239a793bbe8eca6ca10e9ac1a74e51f nginx-mod-stream-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: cf8647d9fd933d04a0adb65057273e2077deb7096a476218f03fb1c7cb7a3e2f nginx-mod-stream-debuginfo-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: e654bde6441825ac9466b573e7c3d116c355f79b9c40423306a3d678c90ed022 nginx-all-modules-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.noarch.rpm SHA-256: db3bff4d79ca48254d71d87db95062732526639f88241e6f87e2adf3f70e4994 nginx-filesystem-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.noarch.rpm SHA-256: a9e55364f10808f8f2e7ce723a6c808027b446e3d3b27c16e63499b89605c34e nginx-all-modules-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.noarch.rpm SHA-256: db3bff4d79ca48254d71d87db95062732526639f88241e6f87e2adf3f70e4994 nginx-filesystem-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.noarch.rpm SHA-256: a9e55364f10808f8f2e7ce723a6c808027b446e3d3b27c16e63499b89605c34e Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM nginx-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.src.rpm SHA-256: ab8b32a9dd7a5611281c557630784ebacd52506e360384c5e502f3f02dc02481 x86_64 nginx-all-modules-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.noarch.rpm SHA-256: db3bff4d79ca48254d71d87db95062732526639f88241e6f87e2adf3f70e4994 nginx-filesystem-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.noarch.rpm SHA-256: a9e55364f10808f8f2e7ce723a6c808027b446e3d3b27c16e63499b89605c34e nginx-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: 5c677318f82fd42972a2e0230483e49875f4783ac30740058051214ddef07144 nginx-all-modules-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.noarch.rpm SHA-256: db3bff4d79ca48254d71d87db95062732526639f88241e6f87e2adf3f70e4994 nginx-core-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: 943f2f8f2201a123419b0508bd3d32ab71fc7ec074671d9093d7402536f682e3 nginx-core-debuginfo-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: e247a4467220b2275770c1745b6337e8b832ce566e98a5d42385322c3f3f0a56 nginx-debuginfo-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: 9a25be853076563d2cb964606940510a04708d29668fcbcd88d9ad9b01ce620d nginx-debugsource-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: d3231be62efab92683496f11f8e903b92ece2204c57959763c338e01872f43e9 nginx-filesystem-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.noarch.rpm SHA-256: a9e55364f10808f8f2e7ce723a6c808027b446e3d3b27c16e63499b89605c34e nginx-mod-devel-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: bd127683d0e2cea047532df6ec3bb8739cf100909ae3324d7d3088097f86fee6 nginx-mod-http-image-filter-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: 393973bca6909e8dba8dd1c536ebd000573703d0abf6511c5bd593370deb9831 nginx-mod-http-image-filter-debuginfo-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: 95b132cf2b07cb24157e60ea53a71b675fc6d9eba7d24364861d2d3712509e49 nginx-mod-http-perl-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: 399284bdeeacbdfe91b8b709e4fd67841f8210ac39c3d447daabfed2e50d9e07 nginx-mod-http-perl-debuginfo-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: 38b79e0766d0708ccacc945eb17a0bf8e7da64938b147bfb9f7d8d5d463fc059 nginx-mod-http-xslt-filter-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: 8a24a969beaf321c41039c56d51020860c9da558fb5408c116a274ae77401b79 nginx-mod-http-xslt-filter-debuginfo-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: 6d5586393fffe1c5ab849e31af9c5b414ae23b1fd51f855f61893903683a5333 nginx-mod-mail-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: 18f70229e059a9a6f6b61d5430f8158007926e362110824227d2ba83532120c4 nginx-mod-mail-debuginfo-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: 404e1451b8e200b05f7bda9f2a683612d239a793bbe8eca6ca10e9ac1a74e51f nginx-mod-stream-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: cf8647d9fd933d04a0adb65057273e2077deb7096a476218f03fb1c7cb7a3e2f nginx-mod-stream-debuginfo-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.x86_64.rpm SHA-256: e654bde6441825ac9466b573e7c3d116c355f79b9c40423306a3d678c90ed022 nginx-all-modules-1.24.0-7.module+el9.8.0+24502+c9b9ab67.3.noarch.rpm SHA-256: db3bff4d79ca48254d71d87db9506
A heap-based buffer overflow vulnerability (CVE-2026-42055, CVSS 8.1 High) in nginx allows for arbitrary code execution or denial of service via crafted HTTP/2 headers. The article states the vulnerability affects the nginx:1.24 module for RHEL 9, while authoritative NVD data lists affected versions for F5 NGINX App Protect WAF (4.10.0-4.16.0, 5.2.0-5.8.0), App Protect DoS (4.3.0-4.7.0), and NGINX Gateway Fabric (1.3.0-1.6.2). The fixed versions per NVD are 2.6.4, 5.5.1, and 1.30.3 for the respective F5 product lines.