Re: nginx-1.30.2_2,3 wrongly vulnerable to CVE-2026-9256 ?
Fernando ApesteguĂa <[email protected]> Fri, 5 Jun 2026 15:35:18 +0200
| Newsgroups | gmane.os.freebsd.security.general |
|---|---|
| Message-ID | <CAGwOe2brbehmLSiDdsvFrOq4SVwGid3RU1-mVNsQOm7kRCgRpQ@mail.gmail.com> |
--00000000000006b5f7065381bc37 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable El vie, 5 jun 2026, 14:47, Arnaud de Prelle <[email protected]> escribi=C3= =B3: > Hi all, > > Thank you for your adaptations. > > Alert has now disappeared from pkg audit -F as the vuXML database now > shows : > 0.1.17,3 <=3D nginx < 1.30.2_2,3 > 1.31.0,3 <=3D nginx < 1.31.1,3 > > Kind regards, > Arnaud. > Thank you all for reporting and sorry for the mistake. > On 2026-06-01 22:42, Fernando Apestegu=C3=ADa wrote: > > Including joneum@ who maintains the port. > > > > On Mon, Jun 1, 2026 at 2:26=E2=80=AFPM Martin Simmons <martin@lispworks= .com> > > wrote: > > > >> [fernape@ added] > >> > >> >>>>> On Sun, 31 May 2026 22:01:11 +0200, Arnaud de Prelle said: > >> > > >> > Hi, > >> > > >> > As per > >> > - https://www.freshports.org/www/nginx/ and > >> > - > >> > > >> > https://vuxml.freebsd.org/freebsd/36a3131d-5600-11f1-b339-3497f65b111b.ht= ml > >> > CVE-2026-9256 should be fixed since nginx 1.30.2,3. > >> > >> The contents of this URL was stale -- the VuXML now says nginx < > >> 1.31.1,3 > >> (since yesterday), which explains why pkg audit is detecting it. > >> > >> > I'm using the latest version of nginx: > >> > # pkg info nginx | grep Version > >> > Version : 1.30.2_2,3 > >> > > >> > But pkg audit -F reports this port as vulnerable to CVE-2026-9256: > >> > # pkg audit -F > >> > vulnxml file up-to-date > >> > nginx-1.30.2_2,3 is vulnerable: > >> > nginx -- heap buffer overflow in ngx_http_rewrite_module > >> > CVE: CVE-2026-9256 > >> > WWW: > >> > > >> > https://vuxml.FreeBSD.org/freebsd/36a3131d-5600-11f1-b339-3497f65b111b.ht= ml > >> > > >> > Am I missing something ? > >> > >> The VuXML looks wrong to me now. > >> > >> nginx released both 1.30.2 and 1.31.1 to fix this CVE > >> (https://nginx.org/en/CHANGES-1.30 and https://nginx.org/en/CHANGES). > >> > >> __Martin > >> > --00000000000006b5f7065381bc37 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"auto"><div><br><br><div class=3D"gmail_quote gmail_quote_contai= ner"><div dir=3D"ltr" class=3D"gmail_attr">El vie, 5 jun 2026, 14:47, Arnau= d de Prelle <<a href=3D"mailto:[email protected]">[email protected]</a>&= gt; escribi=C3=B3:<br></div><blockquote class=3D"gmail_quote" style=3D"marg= in:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi all,<br> <br> Thank you for your adaptations.<br> <br> Alert has now disappeared from pkg audit -F as the vuXML database now <br> shows :<br> 0.1.17,3=C2=A0 =C2=A0 =C2=A0 =C2=A0 <=3D=C2=A0 =C2=A0 =C2=A0 nginx=C2=A0= =C2=A0<=C2=A0 =C2=A0 =C2=A0 =C2=A01.30.2_2,3<br> 1.31.0,3=C2=A0 =C2=A0 =C2=A0 =C2=A0 <=3D=C2=A0 =C2=A0 =C2=A0 nginx=C2=A0= =C2=A0<=C2=A0 =C2=A0 =C2=A0 =C2=A01.31.1,3<br> <br> Kind regards,<br> Arnaud.<br></blockquote></div></div><div dir=3D"auto"><br></div><div dir=3D= "auto">Thank you all for reporting and sorry for the mistake.</div><div dir= =3D"auto"><br></div><div dir=3D"auto"><div class=3D"gmail_quote gmail_quote= _container"><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;bo= rder-left:1px #ccc solid;padding-left:1ex"> <br> On 2026-06-01 22:42, Fernando Apestegu=C3=ADa wrote:<br> > Including joneum@ who maintains the port.<br> > <br> > On Mon, Jun 1, 2026 at 2:26=E2=80=AFPM Martin Simmons <<a href=3D"m= ailto:[email protected]" target=3D"_blank" rel=3D"noreferrer">martin@lis= pworks.com</a>> <br> > wrote:<br> > <br> >> [fernape@ added]<br> >> <br> >> >>>>> On Sun, 31 May 2026 22:01:11 +0200, Arnaud de= Prelle said:<br> >> ><br> >> > Hi,<br> >> ><br> >> > As per<br> >> > - <a href=3D"https://www.freshports.org/www/nginx/" rel=3D"no= referrer noreferrer" target=3D"_blank">https://www.freshports.org/www/nginx= /</a> and<br> >> > -<br> >> ><br> >> <a href=3D"https://vuxml.freebsd.org/freebsd/36a3131d-5600-11f1-b3= 39-3497f65b111b.html" rel=3D"noreferrer noreferrer" target=3D"_blank">https= ://vuxml.freebsd.org/freebsd/36a3131d-5600-11f1-b339-3497f65b111b.html</a><= br> >> > CVE-2026-9256 should be fixed since nginx 1.30.2,3.<br> >> <br> >> The contents of this URL was stale -- the VuXML now says nginx <= ; <br> >> 1.31.1,3<br> >> (since yesterday), which explains why pkg audit is detecting it.<b= r> >> <br> >> > I'm using the latest version of nginx:<br> >> > # pkg info nginx | grep Version<br> >> > Version=C2=A0 =C2=A0 =C2=A0 =C2=A0 : 1.30.2_2,3<br> >> ><br> >> > But pkg audit -F reports this port as vulnerable to CVE-2026-= 9256:<br> >> > # pkg audit -F<br> >> > vulnxml file up-to-date<br> >> > nginx-1.30.2_2,3 is vulnerable:<br> >> >=C2=A0 =C2=A0 nginx -- heap buffer overflow in ngx_http_rewrit= e_module<br> >> >=C2=A0 =C2=A0 CVE: CVE-2026-9256<br> >> >=C2=A0 =C2=A0 WWW:<br> >> ><br> >> <a href=3D"https://vuxml.FreeBSD.org/freebsd/36a3131d-5600-11f1-b3= 39-3497f65b111b.html" rel=3D"noreferrer noreferrer" target=3D"_blank">https= ://vuxml.FreeBSD.org/freebsd/36a3131d-5600-11f1-b339-3497f65b111b.html</a><= br> >> ><br> >> > Am I missing something ?<br> >> <br> >> The VuXML looks wrong to me now.<br> >> <br> >> nginx released both 1.30.2 and 1.31.1 to fix this CVE<br> >> (<a href=3D"https://nginx.org/en/CHANGES-1.30" rel=3D"noreferrer n= oreferrer" target=3D"_blank">https://nginx.org/en/CHANGES-1.30</a> and <a h= ref=3D"https://nginx.org/en/CHANGES" rel=3D"noreferrer noreferrer" target= =3D"_blank">https://nginx.org/en/CHANGES</a>).<br> >> <br> >> __Martin<br> >> <br> </blockquote></div></div></div> --00000000000006b5f7065381bc37--