DSA-6278-1

NameDSA-6278-1
Descriptionnginx - security update
SourceDebian
ReferencesCVE-2026-40701, CVE-2026-42934, CVE-2026-42945, CVE-2026-42946

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nginx (PTS)bookworm1.22.1-9+deb12u6vulnerable
bookworm (security)1.22.1-9+deb12u7fixed
trixie1.26.3-3+deb13u4vulnerable
trixie (security)1.26.3-3+deb13u5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nginxsourcebookworm1.22.1-9+deb12u7
nginxsourcetrixie1.26.3-3+deb13u5

Search for package or bug name: Reporting problems