ELA-1797-1 nginx security update

multiple vulnerabilities

2026-08-07
Packagenginx
Version1.14.2-2+deb10u8 (buster)
Related CVEs CVE-2026-42055 CVE-2026-48142 TEMP-1138794-BADE22


Multiple vulnerabilities were discoverd in Nginx, a high-performance web and reverse proxy server, which could result in remote code execution, denial of service or memory disclosure.

CVE-2026-42055

NGINX Open Source has a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.

CVE-2026-48142

NGINX Open Source has a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart.

No CVE assigned yet

HTTP/2 Bomb denial of service.



For Debian 10 buster, these problems have been fixed in version 1.14.2-2+deb10u8.

We recommend that you upgrade your nginx packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.