F5 just published an out-of-band emergency security update for NGINX, calling out multiple vulnerabilities fixed in the corresponding releases. The bulletin discloses 6 issues rated above “medium”: under CVSS 3.1 that’s 4 high-risk + 2 medium; under CVSS 4.0 it includes 2 critical (“重大”) + 3 high-risk + 1 medium. The standout concerns are the two top-scoring CVEs: CVE-2026-42530 and CVE-2026-42055. - CVE-2026-42530 (UAF) involves NGINX Open Source’s ngx_http_v3_module and related Plus/Open Source HTTP/2 proxy + gRPC modules. In certain HTTP/3 QUIC + QPACK paths, an attacker could trigger use-after-free, leading to worker process restarts—and potentially set the stage for RCE by bypassing ASLR in specific scenarios. - CVE-2026-42055 is a heap-based buffer overflow. With specific config combinations (e.g., proxy_http_version=2, grpc_pass using HTTP/2, ignore_invalid_headers disabled, and large_client_header_buffers > 2MB), crafted large headers can overflow memory and crash/restart the process. F5 also notes impacted NGINX-derived products. Patch ASAP; if you can’t, use the provided mitigations (disable HTTP/3 & QUIC modules; remove ignore_invalid_headers off and cap header buffers). #NGINX #CyberSecurity #Vulnerability #PatchManagement #Sysadmin #F5
Want to learn more? Visit Explore the world, stay updated on travel insights and international affairs, and discover authentic stories from real life
评论
发表评论