USN-8398-2: nginx regression | Ubuntu security notices
USN-8398-1 fixed a vulnerability in nginx. The update introduced a
regression causing nginx to crash when being used with external modules.
This update reverts the fix for CVE-2026-49975 pending further
investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that nginx incorrectly handled certain cookie headers in
the HTTP/2 implementation. A remote attacker could possibly use this issue
to cause nginx to consume excessive resources, resulting in a denial of
service.
USN-8398-1 fixed a vulnerability in nginx. The update introduced a
regression causing nginx to crash when being used with external modules.
This update reverts the fix for CVE-2026-49975 pending further
investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that nginx incorrectly handled certain cookie headers in
the HTTP/2 implementation. A remote attacker could possibly use this issue
to cause nginx to consume excessive resources, resulting in a denial of
service.
Read more here: Source link
