stable

nginx-1.30.1-1.fc44, nginx-mod-brotli-1.0.0~rc-9.fc44, & 6 more

FEDORA-2026-094eb13bb1 created by heffer 2 months ago for Fedora 44

nginx-mod-fancyindex:

  • Rebuild for 1.30.1

nginx-mod-headers-more:

  • Rebuild for 1.30.1

nginx-mod-naxsi:

  • Rebuild for 1.30.1

nginx-mod-js-challenge:

  • Rebuild for 1.30.1

nginx-mod-brotli:

  • Rebuild for 1.30.1

nginx-mod-vts:

  • Rebuild for 1.30.1

nginx-mod-modsecurity:

  • Rebuild for 1.30.1

nginx:

  • update to 1.30.1
  • fixes CVE-2026-42926, CVE-2026-42945, CVE-2026-42946, CVE-2026-42934, CVE-2026-40460 and CVE-2026-40701

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2026-094eb13bb1

This update's test gating status has been changed to 'waiting'.

2 months ago

This update's test gating status has been changed to 'ignored'.

2 months ago

This update has been submitted for testing by bodhi.

2 months ago

heffer edited this update.

2 months ago

heffer edited this update.

2 months ago

This update has been pushed to testing.

2 months ago
User Icon vfedorenko provided feedback a month ago
karma
BZ#2477413 CVE-2026-42945 nginx: NGINX: Arbitrary Code Execution Vulnerability [fedora-all]

This update can be pushed to stable now if the maintainer wishes

a month ago
User Icon esoapw provided feedback a month ago
karma
BZ#2477413 CVE-2026-42945 nginx: NGINX: Arbitrary Code Execution Vulnerability [fedora-all]

This update has been submitted for stable by bodhi.

a month ago
User Icon leoleovich provided feedback a month ago
karma
BZ#2477413 CVE-2026-42945 nginx: NGINX: Arbitrary Code Execution Vulnerability [fedora-all]
User Icon salimma commented & provided feedback a month ago
karma

Installs fine in mock

ebranch check-update looks fine, the warnings are false positives

Checking update: FEDORA-2026-094eb13bb1

Branch: f44

Updated packages: nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-js-challenge, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts

Updated Provides (41)

  • config(nginx) (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • config(nginx-core) (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • nginx (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • nginx(aarch-64) (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • nginx(abi) (1.30.0 → 1.30.1)
  • nginx-all-modules (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • nginx-core (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • nginx-core(aarch-64) (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • nginx-filesystem (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • nginx-mod-devel (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • nginx-mod-devel(aarch-64) (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • nginx-mod-http-geoip (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • nginx-mod-http-geoip(aarch-64) (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • nginx-mod-http-image-filter (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • nginx-mod-http-image-filter(aarch-64) (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • nginx-mod-http-perl (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • nginx-mod-http-perl(aarch-64) (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • nginx-mod-http-xslt-filter (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • nginx-mod-http-xslt-filter(aarch-64) (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • nginx-mod-mail (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • nginx-mod-mail(aarch-64) (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • nginx-mod-stream (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • nginx-mod-stream(aarch-64) (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • nginx-mod-stream-geoip (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • nginx-mod-stream-geoip(aarch-64) (2:1.30.0-1.fc44 → 2:1.30.1-1.fc44)
  • perl(nginx) (1.30.0 → 1.30.1)
  • nginx-mod-brotli (1.0.0~rc-8.fc44 → 1.0.0~rc-9.fc44)
  • nginx-mod-brotli(aarch-64) (1.0.0~rc-8.fc44 → 1.0.0~rc-9.fc44)
  • nginx-mod-fancyindex (0.6.0-3.fc44 → 0.6.0-4.fc44)
  • nginx-mod-fancyindex(aarch-64) (0.6.0-3.fc44 → 0.6.0-4.fc44)
  • nginx-mod-headers-more (0.39-8.fc44 → 0.39-9.fc44)
  • nginx-mod-headers-more(aarch-64) (0.39-8.fc44 → 0.39-9.fc44)
  • nginx-mod-js-challenge (0^20230517.gitda6852d-6.fc44 → 0^20230517.gitda6852d-7.fc44)
  • nginx-mod-js-challenge(aarch-64) (0^20230517.gitda6852d-6.fc44 → 0^20230517.gitda6852d-7.fc44)
  • config(nginx-mod-modsecurity) (1.0.4-9.fc44 → 1.0.4-10.fc44)
  • nginx-mod-modsecurity (1.0.4-9.fc44 → 1.0.4-10.fc44)
  • nginx-mod-modsecurity(aarch-64) (1.0.4-9.fc44 → 1.0.4-10.fc44)
  • nginx-mod-naxsi (1.6-16.fc44 → 1.6-17.fc44)
  • nginx-mod-naxsi(aarch-64) (1.6-16.fc44 → 1.6-17.fc44)
  • nginx-mod-vts (0.2.4-8.fc44 → 0.2.4-9.fc44)
  • nginx-mod-vts(aarch-64) (0.2.4-8.fc44 → 0.2.4-9.fc44)

Installability issues (103)

  • nginx: perl(ExtUtils::Embed)
  • nginx: user(nginx)
  • nginx: rtld(GNU_HASH)
  • nginx: ld-linux-aarch64.so.1()(64bit)
  • nginx: ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)
  • nginx: libc.so.6(GLIBC_2.34)(64bit)
  • nginx: libz.so.1()(64bit)
  • nginx: libcrypto.so.3()(64bit)
  • nginx: libcrypto.so.3(OPENSSL_3.0.0)(64bit)
  • nginx: libssl.so.3()(64bit)
  • nginx: libssl.so.3(OPENSSL_3.0.0)(64bit)
  • nginx: filesystem(unmerged-sbin-symlinks)
  • nginx: libpcre2-8.so.0()(64bit)
  • nginx: libpcre2-8.so.0(PCRE2_10.47)(64bit)
  • nginx: libcrypt.so.2()(64bit)
  • nginx: libcrypt.so.2(XCRYPT_2.0)(64bit)
  • nginx: libssl.so.3(OPENSSL_3.2.0)(64bit)
  • nginx: libprofiler.so.0()(64bit)
  • nginx: libssl.so.3(OPENSSL_3.5.0)(64bit)
  • nginx: rtld(GNU_HASH)
  • nginx: ld-linux-aarch64.so.1()(64bit)
  • nginx: ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)
  • nginx: libc.so.6(GLIBC_2.17)(64bit)
  • nginx: libbrotlienc.so.1()(64bit)
  • nginx: pkgconfig(libbrotlienc)
  • nginx: perl(strict)
  • nginx: perl(warnings)
  • nginx: perl(Exporter)
  • nginx: perl(constant)
  • nginx: perl(XSLoader)
  • nginx: perl(ExtUtils::Embed)
  • nginx: rtld(GNU_HASH)
  • nginx: ld-linux-aarch64.so.1()(64bit)
  • nginx: ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)
  • nginx: libc.so.6(GLIBC_2.33)(64bit)
  • nginx: rtld(GNU_HASH)
  • nginx: ld-linux-aarch64.so.1()(64bit)
  • nginx: ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)
  • nginx: libc.so.6(GLIBC_2.17)(64bit)
  • nginx: rtld(GNU_HASH)
  • nginx: ld-linux-aarch64.so.1()(64bit)
  • nginx: ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)
  • nginx: libc.so.6(GLIBC_2.17)(64bit)
  • nginx: libGeoIP.so.1()(64bit)
  • nginx: rtld(GNU_HASH)
  • nginx: ld-linux-aarch64.so.1()(64bit)
  • nginx: ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)
  • nginx: libc.so.6(GLIBC_2.17)(64bit)
  • nginx: libgd.so.3()(64bit)
  • nginx: rtld(GNU_HASH)
  • nginx: ld-linux-aarch64.so.1()(64bit)
  • nginx: ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)
  • nginx: libc.so.6(GLIBC_2.34)(64bit)
  • nginx: perl(strict)
  • nginx: perl(warnings)
  • nginx: perl(Exporter)
  • nginx: libperl.so.5.42()(64bit)
  • nginx: perl(constant)
  • nginx: perl(XSLoader)
  • nginx: perl(:MODULE_COMPAT_5.42.2)
  • nginx: rtld(GNU_HASH)
  • nginx: ld-linux-aarch64.so.1()(64bit)
  • nginx: ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)
  • nginx: libc.so.6(GLIBC_2.17)(64bit)
  • nginx: libxml2.so.2()(64bit)
  • nginx: libxml2.so.2(LIBXML2_2.4.30)(64bit)
  • nginx: libxml2.so.2(LIBXML2_2.6.0)(64bit)
  • nginx: libxslt.so.1()(64bit)
  • nginx: libxslt.so.1(LIBXML2_1.0.11)(64bit)
  • nginx: libxslt.so.1(LIBXML2_1.0.18)(64bit)
  • nginx: libexslt.so.0()(64bit)
  • nginx: rtld(GNU_HASH)
  • nginx: ld-linux-aarch64.so.1()(64bit)
  • nginx: ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)
  • nginx: libc.so.6(GLIBC_2.33)(64bit)
  • nginx: nginx(abi)
  • nginx: rtld(GNU_HASH)
  • nginx: ld-linux-aarch64.so.1()(64bit)
  • nginx: ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)
  • nginx: libc.so.6(GLIBC_2.17)(64bit)
  • nginx: rtld(GNU_HASH)
  • nginx: ld-linux-aarch64.so.1()(64bit)
  • nginx: ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)
  • nginx: libc.so.6(GLIBC_2.17)(64bit)
  • nginx: libmodsecurity.so.3()(64bit)
  • nginx: rtld(GNU_HASH)
  • nginx: ld-linux-aarch64.so.1()(64bit)
  • nginx: ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)
  • nginx: libc.so.6(GLIBC_2.38)(64bit)
  • nginx: pkgconfig(libinjection)
  • nginx: rtld(GNU_HASH)
  • nginx: ld-linux-aarch64.so.1()(64bit)
  • nginx: ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)
  • nginx: libc.so.6(GLIBC_2.33)(64bit)
  • nginx: rtld(GNU_HASH)
  • nginx: ld-linux-aarch64.so.1()(64bit)
  • nginx: ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)
  • nginx: libc.so.6(GLIBC_2.17)(64bit)
  • nginx: libGeoIP.so.1()(64bit)
  • nginx: rtld(GNU_HASH)
  • nginx: ld-linux-aarch64.so.1()(64bit)
  • nginx: ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)
  • nginx: libc.so.6(GLIBC_2.17)(64bit)

Reverse dependencies

  • lemonldap-ng: OK
  • libzypp: OK
  • mailcap: OK
  • munin: OK
  • nextcloud: OK
  • noggin: OK
  • openqa: OK
  • perl-MogileFS-Server: OK
  • php: OK
  • phpMyAdmin: OK
  • roundcubemail: OK
  • rust-nginx-sys: OK
  • sympa: OK
  • web-assets: OK
  • wordpress: OK

Summary: all 15 reverse dependencies OK.

Warning: 103 installability issue(s) found.

BZ#2477413 CVE-2026-42945 nginx: NGINX: Arbitrary Code Execution Vulnerability [fedora-all]

This update has been pushed to stable.

a month ago

Please log in to add feedback.

Metadata
Type
security
Severity
urgent
Karma
4
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
2
Stable by Time
7 days
Dates
submitted
2 months ago
in testing
2 months ago
in stable
a month ago
modified
2 months ago
approved
a month ago
BZ#2477413 CVE-2026-42945 nginx: NGINX: Arbitrary Code Execution Vulnerability [fedora-all]
0
4

Automated Test Results