Re: nginx-1.30.2_2,3 wrongly vulnerable to CVE-2026-9256 ?
Fernando ApesteguĂa <[email protected]> Mon, 1 Jun 2026 22:42:16 +0200
| Newsgroups | gmane.os.freebsd.security.general |
|---|---|
| Message-ID | <CAGwOe2ZdZ=M4dunqTtSk6J=9cwJKuCzg8u9C9hOg2t2Sf80opQ@mail.gmail.com> |
--0000000000009ff0520653373b3c Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Including joneum@ who maintains the port. On Mon, Jun 1, 2026 at 2:26=E2=80=AFPM Martin Simmons <[email protected]= > wrote: > [fernape@ added] > > >>>>> On Sun, 31 May 2026 22:01:11 +0200, Arnaud de Prelle said: > > > > Hi, > > > > As per > > - https://www.freshports.org/www/nginx/ and > > - > > > https://vuxml.freebsd.org/freebsd/36a3131d-5600-11f1-b339-3497f65b111b.ht= ml > > CVE-2026-9256 should be fixed since nginx 1.30.2,3. > > The contents of this URL was stale -- the VuXML now says nginx < 1.31.1,3 > (since yesterday), which explains why pkg audit is detecting it. > > > I'm using the latest version of nginx: > > # pkg info nginx | grep Version > > Version : 1.30.2_2,3 > > > > But pkg audit -F reports this port as vulnerable to CVE-2026-9256: > > # pkg audit -F > > vulnxml file up-to-date > > nginx-1.30.2_2,3 is vulnerable: > > nginx -- heap buffer overflow in ngx_http_rewrite_module > > CVE: CVE-2026-9256 > > WWW: > > > https://vuxml.FreeBSD.org/freebsd/36a3131d-5600-11f1-b339-3497f65b111b.ht= ml > > > > Am I missing something ? > > The VuXML looks wrong to me now. > > nginx released both 1.30.2 and 1.31.1 to fix this CVE > (https://nginx.org/en/CHANGES-1.30 and https://nginx.org/en/CHANGES). > > __Martin > --0000000000009ff0520653373b3c Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div>Including joneum@ who maintains the port.</div><br><d= iv class=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class=3D"gm= ail_attr">On Mon, Jun 1, 2026 at 2:26=E2=80=AFPM Martin Simmons <<a href= =3D"mailto:[email protected]">[email protected]</a>> wrote:<br></d= iv><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;bord= er-left:1px solid rgb(204,204,204);padding-left:1ex">[fernape@ added]<br> <br> >>>>> On Sun, 31 May 2026 22:01:11 +0200, Arnaud de Prelle s= aid:<br> > <br> > Hi,<br> > <br> > As per<br> > - <a href=3D"https://www.freshports.org/www/nginx/" rel=3D"noreferrer"= target=3D"_blank">https://www.freshports.org/www/nginx/</a> and<br> > - <br> > <a href=3D"https://vuxml.freebsd.org/freebsd/36a3131d-5600-11f1-b339-3= 497f65b111b.html" rel=3D"noreferrer" target=3D"_blank">https://vuxml.freebs= d.org/freebsd/36a3131d-5600-11f1-b339-3497f65b111b.html</a><br> > CVE-2026-9256 should be fixed since nginx 1.30.2,3.<br> <br> The contents of this URL was stale -- the VuXML now says nginx < 1.31.1,= 3<br> (since yesterday), which explains why pkg audit is detecting it.<br> <br> > I'm using the latest version of nginx:<br> > # pkg info nginx | grep Version<br> > Version=C2=A0 =C2=A0 =C2=A0 =C2=A0 : 1.30.2_2,3<br> > <br> > But pkg audit -F reports this port as vulnerable to CVE-2026-9256:<br> > # pkg audit -F<br> > vulnxml file up-to-date<br> > nginx-1.30.2_2,3 is vulnerable:<br> >=C2=A0 =C2=A0 nginx -- heap buffer overflow in ngx_http_rewrite_module<= br> >=C2=A0 =C2=A0 CVE: CVE-2026-9256<br> >=C2=A0 =C2=A0 WWW: <br> > <a href=3D"https://vuxml.FreeBSD.org/freebsd/36a3131d-5600-11f1-b339-3= 497f65b111b.html" rel=3D"noreferrer" target=3D"_blank">https://vuxml.FreeBS= D.org/freebsd/36a3131d-5600-11f1-b339-3497f65b111b.html</a><br> > <br> > Am I missing something ?<br> <br> The VuXML looks wrong to me now.<br> <br> nginx released both 1.30.2 and 1.31.1 to fix this CVE<br> (<a href=3D"https://nginx.org/en/CHANGES-1.30" rel=3D"noreferrer" target=3D= "_blank">https://nginx.org/en/CHANGES-1.30</a> and <a href=3D"https://nginx= .org/en/CHANGES" rel=3D"noreferrer" target=3D"_blank">https://nginx.org/en/= CHANGES</a>).<br> <br> __Martin<br> </blockquote></div></div> --0000000000009ff0520653373b3c--