Skip to content

Update nginx to 1.30.4 to fix CVE-2026-42533 (4.0 branch) - #1665

Open
Mosherfist wants to merge 1 commit into
vmware:4.0from
Mosherfist:fix/nginx-cve-2026-42533-4.0-branch
Open

Update nginx to 1.30.4 to fix CVE-2026-42533 (4.0 branch)#1665
Mosherfist wants to merge 1 commit into
vmware:4.0from
Mosherfist:fix/nginx-cve-2026-42533-4.0-branch

Conversation

@Mosherfist

Copy link
Copy Markdown

Follow-up to #1663 for the 4.0 branch, per @danielxdd's request.

Summary

Bumps nginx from 1.26.3 to 1.30.4 on the 4.0 branch to fix
CVE-2026-42533, a critical heap buffer overflow (CVSS 9.2) in nginx's
map directive regex handling.

Changes

Note: this branch has no config.yaml (unlike main/5.0); the source
checksum is defined inline via %define sha512 in the spec file.

References

Testing

Not build-tested locally; relying on CI for build validation.

Fixes a critical heap buffer overflow in nginx's map directive regex
handling (CVSS 9.2). The vulnerable range is 0.9.6 through 1.31.2;
this bumps the 4.0 branch's nginx package to the patched 1.30.4
stable release.

The ten CVE backport patches (CVE-2025-53859, CVE-2026-27654,
CVE-2026-32647, CVE-2026-27651, CVE-2026-27784, CVE-2026-1642,
CVE-2026-28753, CVE-2026-42945-1, CVE-2026-42945-2, CVE-2026-9256)
previously applied on top of 1.26.3 are dropped, as all ten fixes
are included upstream in 1.30.4.

See: https://nginx.org/en/CHANGES
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant