Ubuntu Security Update USN-8398-2: nginx regression

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,911
Reaction score
75
Credits
-1,257
USN-8398-1 fixed a vulnerability in nginx. The update introduced a regression causing nginx to crash when being used with external modules. This update reverts the fix for CVE-2026-49975 pending further investigation. We apologize for the inconvenience. Original advisory details: It was discovered that nginx incorrectly handled certain cookie headers in the HTTP/2 implementation. A remote attacker could possibly use this issue to cause nginx to consume excessive resources, resulting in a denial of service.

Continue reading...
 


Follow Linux.org

Staff online

Members online


Latest posts

Top