UbuntuUpdates.org

Package "nginx-dev"

Name: nginx-dev

Description:

nginx web/proxy server - development headers

Latest version: 1.28.3-2ubuntu1.7
Release: resolute (26.04)
Level: updates
Repository: universe
Head package: nginx
Homepage: https://nginx.org

Links


Download "nginx-dev"


Other versions of "nginx-dev" in Resolute

Repository Area Version
base universe 1.28.3-2ubuntu1
security universe 1.28.3-2ubuntu1.8

Changelog

Version: 1.28.3-2ubuntu1.7 2026-07-20 21:08:52 UTC
No changelog available yet.
Source diff to previous version

Version: 1.28.3-2ubuntu1.6 2026-06-22 18:07:40 UTC

  nginx (1.28.3-2ubuntu1.6) resolute-security; urgency=medium

  * SECURITY UPDATE: heap overflow via large headers
    - debian/patches/CVE-2026-42055.patch: limit header length for HTTP/2 and
      gRPC in src/http/modules/ngx_http_grpc_module.c.
    - CVE-2026-42055
  * SECURITY UPDATE: heap overread in ngx_http_charset_module
    - debian/patches/CVE-2026-48142.patch: Charset: fixed another rare buffer
      overread in recode_from_utf8() in
      src/http/modules/ngx_http_charset_filter_module.c.
    - CVE-2026-48142

 -- Marc Deslauriers <email address hidden> Fri, 19 Jun 2026 09:25:16 -0400

Source diff to previous version
CVE-2026-42055 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists whe
CVE-2026-48142 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location blo

Version: 1.28.3-2ubuntu1.5 2026-06-15 19:07:46 UTC

  nginx (1.28.3-2ubuntu1.5) resolute-security; urgency=medium

  * SECURITY UPDATE: HTTP/2 Bomb denial of service
    - debian/patches/CVE-2026-49975.patch: updated to patch from Debian's
      1.26.3-3+deb13u6 package which was modified to not break ABI by
      storing the information in a new ngx_http_header_count_module module.
      Thanks to Miao Wang and Jan Mojžíš for the modified patch!
    - CVE-2026-49975

 -- Marc Deslauriers <email address hidden> Wed, 10 Jun 2026 16:06:43 -0400

Source diff to previous version
CVE-2026-49975 Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. T

Version: 1.28.3-2ubuntu1.4 2026-06-09 17:07:39 UTC

  nginx (1.28.3-2ubuntu1.4) resolute-security; urgency=medium

  * SECURITY REGRESSION: ABI change breaking external modules (LP: #2155992)
    - debian/patches/CVE-2026-49975.patch: disable for now, pending further
      investigation.

 -- Marc Deslauriers <email address hidden> Tue, 09 Jun 2026 07:43:21 -0400

Source diff to previous version
CVE-2026-49975 Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. T

Version: 1.28.3-2ubuntu1.3 2026-06-08 17:07:46 UTC

  nginx (1.28.3-2ubuntu1.3) resolute-security; urgency=medium

  * SECURITY UPDATE: HTTP/2 Bomb denial of service
    - debian/patches/CVE-2026-49975.patch: Added max_headers directive. in
      src/http/ngx_http_core_module.c, src/http/ngx_http_core_module.h,
      src/http/ngx_http_request.c, src/http/ngx_http_request.h,
      src/http/v2/ngx_http_v2.c, src/http/v3/ngx_http_v3_request.c.
    - CVE-2026-49975

 -- Marc Deslauriers <email address hidden> Fri, 05 Jun 2026 07:24:46 -0400




About   -   Send Feedback to @ubuntu_updates