Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:59362: Important: nginx security update

A heap buffer over-read (CVE-2026-56434, CVSS 6.5) and a memory disclosure/DoS flaw in the ngx_http_slice_module (CVE-2026-60005, CVSS 8.2) affect nginx. The vulnerabilities impact F5 NGINX Gateway Fabric versions 1.3.0-1.6.2 and 2.0.0 to below 2.6.7, as well as F5 NGINX Ingress Controller versions 3.5.0-3.7.2, 5.0.0 to below 5.5.3, and 2026-lts-r1 to below 2026-lts-r4. Remediation requires upgrading to NGINX Gateway Fabric 2.6.7 or NGINX Ingress Controller 5.5.3 or 2026-lts-r4, respectively.
Read Full Article →

Red Hat Product Errata RHSA-2026:59362 - Security Advisory Issued: 2026-08-25 Updated: 2026-08-25 RHSA-2026:59362 - Security Advisory Overview Updated Packages Synopsis Important: nginx security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for nginx is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage. Security Fix(es): nginx: NGINX: Heap buffer over-read allows memory modification or denial of service (CVE-2026-56434) nginx: NGINX: Memory disclosure and denial of service in ngx_http_slice_module (CVE-2026-60005) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat CodeReady Linux Builder for x86_64 9 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le Red Hat CodeReady Linux Builder for ARM 64 9 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.8 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2500960 - CVE-2026-56434 nginx: NGINX: Heap buffer over-read allows memory modification or denial of service BZ - 2500992 - CVE-2026-60005 nginx: NGINX: Memory disclosure and denial of service in ngx_http_slice_module CVEs CVE-2026-56434 CVE-2026-60005 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM nginx-1.20.1-28.el9_8.5.src.rpm SHA-256: 73fad54a25ddd764b93d9c28403aefe8cad3e274cc0d9a7c74a0861374e373ea x86_64 nginx-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: 4434134fe86e0bb445beaa624661cf3d25d14e30fe0c8b9af78a0d2c2a042777 nginx-all-modules-1.20.1-28.el9_8.5.noarch.rpm SHA-256: 4178dacd3a501fef3382094f057a4a4159fc92452a217b944ef2ba1aec92e32c nginx-core-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: f3b57f41db3765603f2b195aed9b2410a3803e20a31d84bd4b22f820a38f9955 nginx-core-debuginfo-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: b2a59aadbbe773d3edcef96a2bfab8087ede80db78f39eb12a87118a5bf154fd nginx-debuginfo-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: 340ec014b7b7bfca09ccf9121a53c7978de97d0148339ae0336560ba48ebfa0b nginx-debugsource-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: 7bbe8ccdfaa917008b346d1bb69cc93372ef31a1b0614f66369d8c2cece0df5e nginx-filesystem-1.20.1-28.el9_8.5.noarch.rpm SHA-256: dd719c68fb0a659400ba0a82f460ecc60bc287ee587776b548899d3a9f78b723 nginx-mod-http-image-filter-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: a33c8e91dea24892fb5e43eb1402de3e1d1f3b0d2a0ad420a2b756a74ff1851c nginx-mod-http-image-filter-debuginfo-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: a15509b1fc42069c8f3bc769b74289af02178f1c4f83a52ad3b85fb9d2680e8b nginx-mod-http-perl-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: 6574c89763680860ee9574d1a51da208fc9c32dc68abbf2711d2d38b9d76d118 nginx-mod-http-perl-debuginfo-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: a390e07dfffcfc8a3dce3ce72a16509b44a8bab9d5fd46ebe51cf39df32885e5 nginx-mod-http-xslt-filter-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: b1a6f085c2fe9bfbdeac655451a1c3293db669f056c617e11ff2f4dbdd4e35be nginx-mod-http-xslt-filter-debuginfo-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: cd2f36a8a0553424c644e140446e244f795aa952b1ccb0230751e5ba93e8cd6a nginx-mod-mail-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: ea192f43f915373c255c2c3c0c25d14e7243f0a22c3ee2d18e4f18b6278524c3 nginx-mod-mail-debuginfo-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: 1db36e5a0697b982723dd29a820b8b1002c08a41c8efc9267dcab0f4e2191e78 nginx-mod-stream-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: f9117e9beb9426d8653bf42c29e8411a02e34dcadc1bccdf51a83882339a4b48 nginx-mod-stream-debuginfo-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: 4293218ad765a14bbd8ed4f1c85e9918b091bfaa70071d1d5c902b3d25391c53 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM nginx-1.20.1-28.el9_8.5.src.rpm SHA-256: 73fad54a25ddd764b93d9c28403aefe8cad3e274cc0d9a7c74a0861374e373ea x86_64 nginx-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: 4434134fe86e0bb445beaa624661cf3d25d14e30fe0c8b9af78a0d2c2a042777 nginx-all-modules-1.20.1-28.el9_8.5.noarch.rpm SHA-256: 4178dacd3a501fef3382094f057a4a4159fc92452a217b944ef2ba1aec92e32c nginx-core-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: f3b57f41db3765603f2b195aed9b2410a3803e20a31d84bd4b22f820a38f9955 nginx-core-debuginfo-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: b2a59aadbbe773d3edcef96a2bfab8087ede80db78f39eb12a87118a5bf154fd nginx-debuginfo-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: 340ec014b7b7bfca09ccf9121a53c7978de97d0148339ae0336560ba48ebfa0b nginx-debugsource-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: 7bbe8ccdfaa917008b346d1bb69cc93372ef31a1b0614f66369d8c2cece0df5e nginx-filesystem-1.20.1-28.el9_8.5.noarch.rpm SHA-256: dd719c68fb0a659400ba0a82f460ecc60bc287ee587776b548899d3a9f78b723 nginx-mod-http-image-filter-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: a33c8e91dea24892fb5e43eb1402de3e1d1f3b0d2a0ad420a2b756a74ff1851c nginx-mod-http-image-filter-debuginfo-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: a15509b1fc42069c8f3bc769b74289af02178f1c4f83a52ad3b85fb9d2680e8b nginx-mod-http-perl-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: 6574c89763680860ee9574d1a51da208fc9c32dc68abbf2711d2d38b9d76d118 nginx-mod-http-perl-debuginfo-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: a390e07dfffcfc8a3dce3ce72a16509b44a8bab9d5fd46ebe51cf39df32885e5 nginx-mod-http-xslt-filter-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: b1a6f085c2fe9bfbdeac655451a1c3293db669f056c617e11ff2f4dbdd4e35be nginx-mod-http-xslt-filter-debuginfo-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: cd2f36a8a0553424c644e140446e244f795aa952b1ccb0230751e5ba93e8cd6a nginx-mod-mail-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: ea192f43f915373c255c2c3c0c25d14e7243f0a22c3ee2d18e4f18b6278524c3 nginx-mod-mail-debuginfo-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: 1db36e5a0697b982723dd29a820b8b1002c08a41c8efc9267dcab0f4e2191e78 nginx-mod-stream-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: f9117e9beb9426d8653bf42c29e8411a02e34dcadc1bccdf51a83882339a4b48 nginx-mod-stream-debuginfo-1.20.1-28.el9_8.5.x86_64.rpm SHA-256: 4293218ad765a14bbd8ed4f1c85e9918b091bfaa70071d1d5c902b3d25391c53 Red Hat Enterprise Linux for IBM z Systems 9 SRPM nginx-1.20.1-28.el9_8.5.src.rpm SHA-256: 73fad54a25ddd764b93d9c28403aefe8cad3e274cc0d9a7c74a0861374e373ea s390x nginx-1.20.1-28.el9_8.5.s390x.rpm SHA-256: 8c8a4ec35fe8710d9b068e72b1f14defe2c5689b868a7d483a7d6482daad1864 nginx-all-modules-1.20.1-28.el9_8.5.noarch.rpm SHA-256: 4178dacd3a501fef3382094f057a4a4159fc92452a217b944ef2ba1aec92e32c nginx-core-1.20.1-28.el9_8.5.s390x.rpm SHA-256: 79461e9583e61d5a0206678edf9ab59253826b2706916d0c7f1d00160204455a nginx-core-debuginfo-1.20.1-28.el9_8.5.s390x.rpm SHA-256: 8949d238ef7c2643a5dd6bfd599ce441a7a1883f74a5c512504d70cd39248733 nginx-debuginfo-1.20.1-28.el9_8.5.s390x.rpm SHA-256: a5a485ba6a7c75473ce22eaa18314cd8f55e220699f8ae7652f9896689bb0ff7 nginx-debugsource-1.20.1-28.el9_8.5.s390x.rpm SHA-256: f1de47f6cfc43a248b4bcbc64e2f7ad86f2aa4d951e15e79a02915161861a4e1 nginx-filesystem-1.20.1-28.el9_8.5.noarch.rpm SHA-256: dd719c68fb0a659400ba0a82f460ecc60bc287ee587776b548899d3a9f78b723 nginx-mod-http-image-filter-1.20.1-28.el9_8.5.s390x.rpm SHA-256: 95edd1c093a06a00276001e5a8b6db802fa91aa44f2e9ba7685820224938a5da nginx-mod-http-image-filter-debuginfo-1.20.1-28.el9_8.5.s390x.rpm SHA-256: 6f9c4456a973c5b3418051d1131eafd404abfbb022c7f757811541f25c71c021 nginx-mod-http-perl-1.20.1-28.el9_8.5.s390x.rpm SHA-256: 3d2068f45d0f55975a5e9503a090505eb832899b006c98853f6b788b890a742f nginx-mod-http-perl-debuginfo-1.20.1-28.el9_8.5.s390x.rpm SHA-256: 53833fa4e5fc21428313d058962943a537e86ef00689bb6b1f7f1ba6e03ce7c4 nginx-mod-http-xslt-filter-1.20.1-28.el9_8.5.s390x.rpm SHA-256: c105dc908d2eb4e19a782f6d90ab15aa9748110b9f73c5b2a2cc909f232132a8 nginx-mod-http-xslt-filter-debuginfo-1.20.1-28.el9_8.5.s390x.rpm SHA-256: ee164b2c392956bd7449ae1e4c59a1ea7b1d754a3aac81c50e3181a4b37b74b5 nginx-mod-mail-1.20.1-28.el9_8.5.s390x.rpm SHA-256: 2fd2

Share this article