Update nginx to 1.30.4 to fix CVE-2026-42533 (5.0 branch) - #1664
Update nginx to 1.30.4 to fix CVE-2026-42533 (5.0 branch)#1664Mosherfist wants to merge 1 commit into
Conversation
Fixes a critical heap buffer overflow in nginx's map directive regex handling (CVSS 9.2). The vulnerable range is 0.9.6 through 1.31.2; this bumps the 5.0 branch's nginx package to the patched 1.30.4 stable release. The six CVE backport patches (CVE-2025-53859, CVE-2026-27654, CVE-2026-32647, CVE-2026-27651, CVE-2026-27784, CVE-2026-1642) previously applied on top of 1.26.3 are dropped, as all six fixes are included upstream in 1.30.4. See: https://nginx.org/en/CHANGES
🛑 Legal Compliance Check FailedHi @Mosherfist, thank you for your contribution! To merge this Pull Request, you must sign our DCO. Note: Even if you signed off your commits locally (using 1. Read the Document: Click here to read the DCO ⏳ Processing Schedule: |
Follow-up to #1663 for the 5.0 branch, per @danielxdd's request.
Summary
Bumps nginx from 1.26.3 to 1.30.4 on the 5.0 branch to fix
CVE-2026-42533, a critical heap buffer overflow (CVSS 9.2) in nginx's
map directive regex handling.
Changes
CVE-2026-32647, CVE-2026-27651, CVE-2026-27784, CVE-2026-1642) that
were applied on top of 1.26.3 — all six are included upstream in
1.30.4, so re-applying them would either be redundant or fail to
apply against the updated source.
References
Testing
Not build-tested locally (RPM toolchain build not set up on my
machine); relying on CI for build validation.