RBlind
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
WPSteam@lemmy.world to cybersecurity@infosec.pub · 11 days ago

CVE-2026-42530 & CVE-2026-42055: NGINX RCE Flaws Explained. Patches Released

thecybersecguru.com

external-link
message-square
4
link
fedilink
21
external-link

CVE-2026-42530 & CVE-2026-42055: NGINX RCE Flaws Explained. Patches Released

thecybersecguru.com

WPSteam@lemmy.world to cybersecurity@infosec.pub · 11 days ago
message-square
4
link
fedilink
CVE-2026-42530 & CVE-2026-42055: NGINX RCE Flaws Explained | The CyberSec Guru
thecybersecguru.com
external-link
F5 patched two critical NGINX flaws (CVSS 9.2): a QPACK use-after-free in HTTP/3 and a gRPC heap overflow. Full technical breakdown and PoCs
alert-triangle
You must log in or # to comment.
  • SamuelEllis@lemmy.worldBanned
    link
    fedilink
    arrow-up
    5
    ·
    edit-2
    3 days ago

    Removed by mod

    • UnLocoPoco@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      10 days ago

      Also, one should not depend on the version of nginx that ships with any particular distro…auch as ubuntu and all cuz generally, they are not the latest versions…best is to simply grab nginx or any package directly from their own repo which will ensure that one always gets the latest version…but again that’s a double edged sword…

      • frongt@lemmy.zip
        link
        fedilink
        arrow-up
        3
        arrow-down
        2
        ·
        10 days ago

        Major distros like Ubuntu backport security fixes to the stable version.

        • UnLocoPoco@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          10 days ago

          Yes but they take a lill time

  • neutronbumblebee@mander.xyz
    link
    fedilink
    arrow-up
    3
    arrow-down
    2
    ·
    edit-2
    11 days ago

    I’ve found PatchMon to be excellent at prioritizing Linux patching for groups of servers. Depending on how critical vs exposed they are. (https://github.com/PatchMon/PatchMon)

cybersecurity@infosec.pub

cybersecurity@infosec.pub

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !cybersecurity@infosec.pub

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Community Rules

  • Be kind
  • Limit promotional activities
  • Non-cybersecurity posts should be redirected to other communities within infosec.pub.

Enjoy!

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 32 users / day
  • 72 users / week
  • 683 users / month
  • 2.29K users / 6 months
  • 2 local subscribers
  • 6.27K subscribers
  • 505 Posts
  • 881 Comments
  • Modlog
  • mods:
  • shellsharks@infosec.pub
  • tweedge@infosec.pub
  • BE: 0.19.19
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org