ELA-1832-1 nginx security update

multiple vulnerabilities

2026-09-26
Packagenginx
Version1.18.0-6.1+deb11u9 (bullseye)
Related CVEs CVE-2026-42533 CVE-2026-56434 CVE-2026-60005


Multiple vulnerabilities were discovered in nginx, a high-performance web and reverse proxy server, which may result in denial of service, memory disclosure or potentially the execution of arbitrary code.

CVE-2026-42533

A heap buffer overflow was discovered in the nginx script engine. It
can be triggered when a map directive performs regular expression
matching and a string expression references captures modified by the
map, or when non-cacheable variables change between the script length
pass and the script copy pass.

CVE-2026-56434

Duplicate finalization of an HTTP subrequest can result in a
use-after-free. The issue is observable in configurations using
server-side includes together with proxy_pass and proxy_buffering
disabled, when an upstream response causes the same subrequest to be
posted twice.

CVE-2026-60005

ngx_http_regex_exec() could replace the captures array without
clearing r->ncaptures when the new regular expression did not match.
A subsequent unnamed capture could then access uninitialised memory,
resulting in memory disclosure.


For Debian 11 bullseye, these problems have been fixed in version 1.18.0-6.1+deb11u9.

We recommend that you upgrade your nginx packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.