Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
红帽产品勘误 RHSA-2026:6408 - Security Advisory
发布:
2026-04-01
已更新:
2026-04-01

RHSA-2026:6408 - Security Advisory

  • 概述
  • 更新的软件包

概述

Moderate: nginx security update

类型/严重性

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

识别并修复受此公告影响的系统。

查看受影响的系统

标题

An update for nginx is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

描述

nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage.

Security Fix(es):

  • nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections (CVE-2026-1642)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

解决方案

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

受影响的产品

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

修复

  • BZ - 2436738 - CVE-2026-1642 nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections

CVE

  • CVE-2026-1642

参考

  • https://access.redhat.com/security/updates/classification/#moderate
注:: 可能有这些软件包的更新版本。 点击软件包名称查看详情。

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
nginx-1.20.1-10.el9_0.2.src.rpm SHA-256: 06f0cf0160d5295ed2486319678c00a87512cff105c26cb11289df3291232056
ppc64le
nginx-1.20.1-10.el9_0.2.ppc64le.rpm SHA-256: 59b2dfe221dd5681d500f09c16a9bb542ee87d5617aa911157d63d28907b9700
nginx-all-modules-1.20.1-10.el9_0.2.noarch.rpm SHA-256: 72ea8614bccc091b065854e88f6c4f227994ebc57b43bedd7be05661cbe45091
nginx-debuginfo-1.20.1-10.el9_0.2.ppc64le.rpm SHA-256: 47b9807d13bc1e81aaa382678052f6251f1e0879aa3430a2afbd6a6baff43afc
nginx-debugsource-1.20.1-10.el9_0.2.ppc64le.rpm SHA-256: 0d351c7d1cc0af2a703cc8c259eec1553ebab8718e9d7e1deaa3c40416c479b2
nginx-filesystem-1.20.1-10.el9_0.2.noarch.rpm SHA-256: 0b58ca85c19411213ee51df86e999ebd412c3364549806678156e98105746497
nginx-mod-http-image-filter-1.20.1-10.el9_0.2.ppc64le.rpm SHA-256: 6095b5506471ce727b562cd05af0f327f94cf898d4fbe3511193a71226698261
nginx-mod-http-image-filter-debuginfo-1.20.1-10.el9_0.2.ppc64le.rpm SHA-256: 3cee50889d36fdf97bfd8d9cee939055086f47d4dddd35e6b23957d276a219d0
nginx-mod-http-perl-1.20.1-10.el9_0.2.ppc64le.rpm SHA-256: 4ba94af3d6187b30d103b51588c2043ffa5577a4d6266f9adcd60334ac871896
nginx-mod-http-perl-debuginfo-1.20.1-10.el9_0.2.ppc64le.rpm SHA-256: 7354d191f260068be20ab929ecc1be31abcac1518091786077c81e495d7a01f1
nginx-mod-http-xslt-filter-1.20.1-10.el9_0.2.ppc64le.rpm SHA-256: e6528aa7be9c81686bfe1761b55a772062445aab884b91efdadbdbd5d3d0be5d
nginx-mod-http-xslt-filter-debuginfo-1.20.1-10.el9_0.2.ppc64le.rpm SHA-256: 040901c9fd03176cf2ef912a0c9d7cd8fa875f00eb094c986f3508dc1220cb29
nginx-mod-mail-1.20.1-10.el9_0.2.ppc64le.rpm SHA-256: ad7cca97d7cd371cea98213c81a24a86112a6b79ac6f0b1cf1b6cdb8609c4336
nginx-mod-mail-debuginfo-1.20.1-10.el9_0.2.ppc64le.rpm SHA-256: 37da21e92dd1386d7ea85c9052b5997310ec0174ebbf793beaae364412be0589
nginx-mod-stream-1.20.1-10.el9_0.2.ppc64le.rpm SHA-256: c7c17c4072977325159964f7a7f6028d867e863009c4f13329487d5a07ebbb12
nginx-mod-stream-debuginfo-1.20.1-10.el9_0.2.ppc64le.rpm SHA-256: 90b2eb982100e68ed9884ee7f31720f7b4e2bb9915be638092f420779e3661fd

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
nginx-1.20.1-10.el9_0.2.src.rpm SHA-256: 06f0cf0160d5295ed2486319678c00a87512cff105c26cb11289df3291232056
x86_64
nginx-1.20.1-10.el9_0.2.x86_64.rpm SHA-256: 522337071b16d5f6e0782ac8108da4a70ff01783e943ebdfbe436cab75915555
nginx-all-modules-1.20.1-10.el9_0.2.noarch.rpm SHA-256: 72ea8614bccc091b065854e88f6c4f227994ebc57b43bedd7be05661cbe45091
nginx-debuginfo-1.20.1-10.el9_0.2.x86_64.rpm SHA-256: cdf5f5c964c9084f12371e901d100dea157bf20f443696a89bc51df45fc391d3
nginx-debugsource-1.20.1-10.el9_0.2.x86_64.rpm SHA-256: 1c07a57b5202a3601e5699173febf91a5b9247dc0d594bb86674f568115019e5
nginx-filesystem-1.20.1-10.el9_0.2.noarch.rpm SHA-256: 0b58ca85c19411213ee51df86e999ebd412c3364549806678156e98105746497
nginx-mod-http-image-filter-1.20.1-10.el9_0.2.x86_64.rpm SHA-256: d15ed0b0e4b773954846ba1f279c49c146470673b67b0360951ff28028a1b240
nginx-mod-http-image-filter-debuginfo-1.20.1-10.el9_0.2.x86_64.rpm SHA-256: 84a0fcca7c926151eb5f865ac68344f1ba3c774bb97716198c81fde76a2c4da1
nginx-mod-http-perl-1.20.1-10.el9_0.2.x86_64.rpm SHA-256: 65ec83ec35e1f0bedfef8716126dd7ae4876b8a0187c47b67e9f00aae8d91437
nginx-mod-http-perl-debuginfo-1.20.1-10.el9_0.2.x86_64.rpm SHA-256: 00b53ee2b680ae6b175c03d44b9cb40d4963f04c8eee581c8475d9a8bf6dc2b4
nginx-mod-http-xslt-filter-1.20.1-10.el9_0.2.x86_64.rpm SHA-256: c5587903cdf73ba1d1bde4811cd736e387c8779c76ede22355ce4894b19b810b
nginx-mod-http-xslt-filter-debuginfo-1.20.1-10.el9_0.2.x86_64.rpm SHA-256: eb1d92148c61f2f93fed906ffc4e2e4d70b2b4f7e3c0746ded2cea54b1bc6414
nginx-mod-mail-1.20.1-10.el9_0.2.x86_64.rpm SHA-256: 15ae168200739f10cdfbdc023e1c0370fbe4efd43faae5f89534430544582f44
nginx-mod-mail-debuginfo-1.20.1-10.el9_0.2.x86_64.rpm SHA-256: 911687978254d2d34f175ca96efac2644803da0dc6e44c5e5a0965cf1380a72d
nginx-mod-stream-1.20.1-10.el9_0.2.x86_64.rpm SHA-256: 1ba1ab03fccf59245f28a9c8e20fa9f0892d4fd773c521724d9c1219fa80a658
nginx-mod-stream-debuginfo-1.20.1-10.el9_0.2.x86_64.rpm SHA-256: 6275b515d18341425368129d2a1676f9324eaaeb9f2ef280ebe58eaf9b99277d

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
nginx-1.20.1-10.el9_0.2.src.rpm SHA-256: 06f0cf0160d5295ed2486319678c00a87512cff105c26cb11289df3291232056
aarch64
nginx-1.20.1-10.el9_0.2.aarch64.rpm SHA-256: 19ae6c61e182a9cf9825fdffc7d33a0fe1ae63287e6f1fb3f0392ba05079ddbf
nginx-all-modules-1.20.1-10.el9_0.2.noarch.rpm SHA-256: 72ea8614bccc091b065854e88f6c4f227994ebc57b43bedd7be05661cbe45091
nginx-debuginfo-1.20.1-10.el9_0.2.aarch64.rpm SHA-256: 90498ab243fd2b79e686a941bb173c0a33a2ae3f7ac6e3776540a02d2fbbb795
nginx-debugsource-1.20.1-10.el9_0.2.aarch64.rpm SHA-256: 92c64852cd49772cb52fe5c7c9fa5047cf75f77561ff47b77c2e7a6bc95f053b
nginx-filesystem-1.20.1-10.el9_0.2.noarch.rpm SHA-256: 0b58ca85c19411213ee51df86e999ebd412c3364549806678156e98105746497
nginx-mod-http-image-filter-1.20.1-10.el9_0.2.aarch64.rpm SHA-256: 8762df724da969f67ea935a4a2ff6fa85f922ed6e6f94eb1f0480ade8011590d
nginx-mod-http-image-filter-debuginfo-1.20.1-10.el9_0.2.aarch64.rpm SHA-256: d0121f4ab846d6a287ef1f9fdc5cc6a8d36582e059559f5a102455f0710793d1
nginx-mod-http-perl-1.20.1-10.el9_0.2.aarch64.rpm SHA-256: b9fb6eb86d977ffb89622e502e8926e79b3735aac226bf88d449bec070b64859
nginx-mod-http-perl-debuginfo-1.20.1-10.el9_0.2.aarch64.rpm SHA-256: 4c26f007e59e9f0d32cf658c90af016c4cd7a2fac0135bbdb83749016c5abebc
nginx-mod-http-xslt-filter-1.20.1-10.el9_0.2.aarch64.rpm SHA-256: d9f9672f1dcdb3db0be0208cf4f2d0df1ce050c41a69c053588e9fdc511bd0c2
nginx-mod-http-xslt-filter-debuginfo-1.20.1-10.el9_0.2.aarch64.rpm SHA-256: c3022f234e3da76e18e61a44a5b0dd2020d521b057fc3d3e75a5d3db6e7817f0
nginx-mod-mail-1.20.1-10.el9_0.2.aarch64.rpm SHA-256: 6055aeb981f5825eead87b07c460c96ad0f6bf63864ca2c819bc899b7f299999
nginx-mod-mail-debuginfo-1.20.1-10.el9_0.2.aarch64.rpm SHA-256: 15f5d9b314edeb3655d925002f8049fa270f7d3516b939764a624ce2e0783310
nginx-mod-stream-1.20.1-10.el9_0.2.aarch64.rpm SHA-256: 200694a93509df6676d58fc9d32d6600d621227a4e5863721b991a6b1696a9c2
nginx-mod-stream-debuginfo-1.20.1-10.el9_0.2.aarch64.rpm SHA-256: 78b9b84ac63331f50328d7367799f254c9f6c73032164c835f156dec16d64bc9

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
nginx-1.20.1-10.el9_0.2.src.rpm SHA-256: 06f0cf0160d5295ed2486319678c00a87512cff105c26cb11289df3291232056
s390x
nginx-1.20.1-10.el9_0.2.s390x.rpm SHA-256: 4459ae80350bc556eec10abd09444c8b215ac774dfb16fb1629210f477046d2e
nginx-all-modules-1.20.1-10.el9_0.2.noarch.rpm SHA-256: 72ea8614bccc091b065854e88f6c4f227994ebc57b43bedd7be05661cbe45091
nginx-debuginfo-1.20.1-10.el9_0.2.s390x.rpm SHA-256: b0267470f0efa0fca69f49b656c69906da9427d851eaf6d3d9e52adbcea5db3e
nginx-debugsource-1.20.1-10.el9_0.2.s390x.rpm SHA-256: 885d26bf6436b1418447e4b493f04603ee802a1808e3d4bad425fded25e6aa0e
nginx-filesystem-1.20.1-10.el9_0.2.noarch.rpm SHA-256: 0b58ca85c19411213ee51df86e999ebd412c3364549806678156e98105746497
nginx-mod-http-image-filter-1.20.1-10.el9_0.2.s390x.rpm SHA-256: 96c6c204dca238292f70a3c9b3ff0d5479bfd01e25210dabbea4ceac85ac021f
nginx-mod-http-image-filter-debuginfo-1.20.1-10.el9_0.2.s390x.rpm SHA-256: a4edf81c2f3e57896cee3973e1ba29074de844685cac9870352a2d95d660c220
nginx-mod-http-perl-1.20.1-10.el9_0.2.s390x.rpm SHA-256: e4f647fbd20cd49872aec25c91a70b3ca227b860cb4eee57f2f04cd9644fdf27
nginx-mod-http-perl-debuginfo-1.20.1-10.el9_0.2.s390x.rpm SHA-256: 657c38f2bbbc2366b3eb0020f7b6a4bb0e706679624c2000091c8025ac88a959
nginx-mod-http-xslt-filter-1.20.1-10.el9_0.2.s390x.rpm SHA-256: 9af94ba92083ccb99a8b5ffa7af7992b17e3aca639c5a8fbd0a9cd91c0997517
nginx-mod-http-xslt-filter-debuginfo-1.20.1-10.el9_0.2.s390x.rpm SHA-256: 679d05072cf490670b633ba4f6263f56d7afdebfdd156777b964a70e05779d47
nginx-mod-mail-1.20.1-10.el9_0.2.s390x.rpm SHA-256: 424d17f5a884de2526202835c5dd963a75cd94ae237491ec136fd3712d577cb8
nginx-mod-mail-debuginfo-1.20.1-10.el9_0.2.s390x.rpm SHA-256: ae8489ff1428317bed1f6a993a82df2851e66bf82f263484c881fc5e9aea4054
nginx-mod-stream-1.20.1-10.el9_0.2.s390x.rpm SHA-256: bab43b4c14515f80362e38d84c3d27d6c8736ea3a1100c208d3a3b2462fc3aae
nginx-mod-stream-debuginfo-1.20.1-10.el9_0.2.s390x.rpm SHA-256: 064ef5530d95eed1c4d3735adcbc03e4380cfc97b9d9371e8627ab64534dde3e

Red Hat 安全团队联络方式为 secalert@redhat.com。 更多联络细节请参考 https://access.redhat.com/security/team/contact/。

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility