Skip to content

Commit 7d50f2b

Browse files
committed
nginx-1.27.1, nginx-1.26.2.
1 parent 444853a commit 7d50f2b

File tree

7 files changed

+75
-4
lines changed

7 files changed

+75
-4
lines changed

text/en/CHANGES

Lines changed: 17 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,20 @@
11

2+
Changes with nginx 1.27.1 14 Aug 2024
3+
4+
*) Security: processing of a specially crafted mp4 file by the
5+
ngx_http_mp4_module might cause a worker process crash
6+
(CVE-2024-7347).
7+
Thanks to Nils Bars.
8+
9+
*) Change: now the stream module handler is not mandatory.
10+
11+
*) Bugfix: new HTTP/2 connections might ignore graceful shutdown of old
12+
worker processes.
13+
Thanks to Kasei Wang.
14+
15+
*) Bugfixes in HTTP/3.
16+
17+
218
Changes with nginx 1.27.0 29 May 2024
319

420
*) Security: when using HTTP/3, processing of a specially crafted QUIC
@@ -15,7 +31,7 @@ Changes with nginx 1.27.0 29 May 2024
1531
*) Bugfix: reduced memory consumption for long-lived requests if "gzip",
1632
"gunzip", "ssi", "sub_filter", or "grpc_pass" directives are used.
1733

18-
*) Bugfix: nginx could not be built by gcc 14 if the --with-atomic
34+
*) Bugfix: nginx could not be built by gcc 14 if the --with-libatomic
1935
option was used.
2036
Thanks to Edgar Bonet.
2137

text/en/CHANGES-1.26

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,12 @@
11

2+
Changes with nginx 1.26.2 14 Aug 2024
3+
4+
*) Security: processing of a specially crafted mp4 file by the
5+
ngx_http_mp4_module might cause a worker process crash
6+
(CVE-2024-7347).
7+
Thanks to Nils Bars.
8+
9+
210
Changes with nginx 1.26.1 29 May 2024
311

412
*) Security: when using HTTP/3, processing of a specially crafted QUIC
@@ -11,7 +19,7 @@ Changes with nginx 1.26.1 29 May 2024
1119
*) Bugfix: reduced memory consumption for long-lived requests if "gzip",
1220
"gunzip", "ssi", "sub_filter", or "grpc_pass" directives are used.
1321

14-
*) Bugfix: nginx could not be built by gcc 14 if the --with-atomic
22+
*) Bugfix: nginx could not be built by gcc 14 if the --with-libatomic
1523
option was used.
1624
Thanks to Edgar Bonet.
1725

text/ru/CHANGES.ru

Lines changed: 18 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,21 @@
11

2+
Изменения в nginx 1.27.1 14.08.2024
3+
4+
*) Безопасность: обработка специально созданного mp4-файла модулем
5+
ngx_http_mp4_module могла приводить к падению рабочего процесса
6+
(CVE-2024-7347).
7+
Спасибо Nils Bars.
8+
9+
*) Изменение: теперь обработчик в модуле stream не является
10+
обязательным.
11+
12+
*) Исправление: новые HTTP/2-соединения могли игнорировать плавное
13+
завершение старых рабочих процессов.
14+
Спасибо Kasei Wang.
15+
16+
*) Исправления в HTTP/3.
17+
18+
219
Изменения в nginx 1.27.0 29.05.2024
320

421
*) Безопасность: при использовании HTTP/3 обработка специально созданной
@@ -16,7 +33,7 @@
1633
grpc_pass.
1734

1835
*) Исправление: nginx не собирался gcc 14, если использовался параметр
19-
--with-atomic.
36+
--with-libatomic.
2037
Спасибо Edgar Bonet.
2138

2239
*) Исправления в HTTP/3.

text/ru/CHANGES.ru-1.26

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,12 @@
11

2+
Изменения в nginx 1.26.2 14.08.2024
3+
4+
*) Безопасность: обработка специально созданного mp4-файла модулем
5+
ngx_http_mp4_module могла приводить к падению рабочего процесса
6+
(CVE-2024-7347).
7+
Спасибо Nils Bars.
8+
9+
210
Изменения в nginx 1.26.1 29.05.2024
311

412
*) Безопасность: при использовании HTTP/3 обработка специально созданной
@@ -13,7 +21,7 @@
1321
grpc_pass.
1422

1523
*) Исправление: nginx не собирался gcc 14, если использовался параметр
16-
--with-atomic.
24+
--with-libatomic.
1725
Спасибо Edgar Bonet.
1826

1927
*) Исправление: в HTTP/3.

xml/en/security_advisories.xml

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,14 @@ Patches are signed using one of the
2424

2525
<security>
2626

27+
<item name="Buffer overread in the ngx_http_mp4_module"
28+
severity="low"
29+
cve="2024-7347"
30+
good="1.27.1+, 1.26.2+"
31+
vulnerable="1.5.13-1.27.0">
32+
<patch name="patch.2024.mp4.txt" />
33+
</item>
34+
2735
<item name="Buffer overwrite in HTTP/3"
2836
severity="medium"
2937
advisory="https://mailman.nginx.org/pipermail/nginx-announce/2024/GMY32CSHFH6VFTN76HJNX7WNEX4RLHF6.html"

xml/index.xml

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,18 @@
77

88
<news name="nginx news" link="/" lang="en">
99

10+
<event date="2024-08-14">
11+
<para>
12+
<link doc="en/download.xml">nginx-1.26.2</link>
13+
stable and
14+
<link doc="en/download.xml">nginx-1.27.1</link>
15+
mainline versions have been released,
16+
with a fix for the
17+
<link doc="en/security_advisories.xml">buffer overread</link>
18+
vulnerability in the ngx_http_mp4_module (CVE-2024-7347).
19+
</para>
20+
</event>
21+
1022
<event date="2024-06-25">
1123
<para>
1224
<link doc="en/docs/njs/index.xml">njs-0.8.5</link>

xml/versions.xml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,13 +9,15 @@
99

1010
<download tag="mainline" changes="">
1111

12+
<item ver="1.27.1" />
1213
<item ver="1.27.0" />
1314

1415
</download>
1516

1617

1718
<download tag="stable" changes="1.26">
1819

20+
<item ver="1.26.2" />
1921
<item ver="1.26.1" />
2022
<item ver="1.26.0" />
2123
<item ver="1.25.5" />

0 commit comments

Comments
 (0)