[SECURITY] Fedora 41 Update: nginx-1.26.3-1.fc41

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-66ebd291f8
2025-02-15 02:35:33.711202+00:00
--------------------------------------------------------------------------------

Name        : nginx
Product     : Fedora 41
Version     : 1.26.3
Release     : 1.fc41
URL         : https://nginx.org
Summary     : A high performance web server and reverse proxy server
Description :
Nginx is a web server and a reverse proxy server for HTTP, SMTP, POP3 and
IMAP protocols, with a strong focus on high concurrency, performance and low
memory usage.

--------------------------------------------------------------------------------
Update Information:

Changes with nginx 1.26.3                                        05 Feb 2025
*) Security: insufficient check in virtual servers handling with TLSv1.3
   SNI allowed to reuse SSL sessions in a different virtual server, to
   bypass client SSL certificates verification (CVE-2025-23419).
*) Bugfix: in the ngx_http_mp4_module.
   Thanks to Nils Bars.
*) Workaround: "gzip filter failed to use preallocated memory" alerts
   appeared in logs when using zlib-ng.
*) Bugfix: nginx could not build libatomic library using the library
   sources if the --with-libatomic=DIR option was used.
*) Bugfix: nginx now ignores QUIC version negotiation packets from
   clients.
*) Bugfix: nginx could not be built on Solaris 10 and earlier with the
   ngx_http_v3_module.
*) Bugfixes in HTTP/3.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Feb  6 2025 Felix Kaechele <felix@xxxxxxxxxxx> - 2:1.26.3-1
- update to 1.26.3
- fixes SSL session reuse vulnerability (CVE-2025-23419)
- drop zlib-ng patch, the issue was addressed upstream
* Wed Feb  5 2025 Luboš Uhliarik <luhliari@xxxxxxxxxx> - 2:1.26.2-6
- Use systemd-sysusers
* Mon Feb  3 2025 Joe Orton <jorton@xxxxxxxxxx> - 2:1.26.2-5
- Add systemd instantiated service nginx@.service, allowing e.g. "systemctl
  start nginx@foobar.service" to start an instance of nginx using
  /etc/nginx/foobar.conf as the configuration.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2277663 - please switch to using systemd-sysusers to create the nginx user
        https://bugzilla.redhat.com/show_bug.cgi?id=2277663
  [ 2 ] Bug #2344198 - CVE-2025-23419 nginx: TLS Session Resumption Vulnerability [fedora-41]
        https://bugzilla.redhat.com/show_bug.cgi?id=2344198
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-66ebd291f8' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

-- 
_______________________________________________
package-announce mailing list -- package-announce@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to package-announce-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@xxxxxxxxxxxxxxxxxxxxxxx
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue

[Index of Archives]     [Fedora Users]     [Fedora Legacy]     [Fedora Desktop]     [Fedora SELinux]     [Big List of Linux Books]     [Yosemite News]     [Yosemite Photos]     [KDE Users]

  Powered by Linux