-
moparisthebest
unauthenticated RCE in nginx, upgrade immediately https://depthfirst.com/nginx-rift
😠1 -
icebound.dev
> unauthenticated RCE in nginx, upgrade immediately https://depthfirst.com/nginx-rift was this also found by anthropics new toy? ↺
-
icebound.dev
Debian doesn't appear to have pushed a DSA for this yet...
-
icebound.dev
https://app.opencve.io/cve/CVE-2026-42945 checking the CVE info, anything below 1.31.0 is vulnerable, Arch Linux updated the package, but Debian is still sitting at 1.26.3
-
Sunglocto (sunglocto.net)
icebound.dev: https://archlinux.org/packages/extra/x86_64/nginx/ shows nginx at 1.30.1-1
-
Sunglocto (sunglocto.net)
hmm actually that package seems to have been updated yesterday
-
icebound.dev
Sunglocto (sunglocto.net), oh I must have misread the version... okay then Arch is vulnerable too :p
-
icebound.dev
all the right numbers are in the string, just not in the right order >:)
-
icebound.dev
good thing OpenBSD httpd isn't affected, like usual :p
-
moparisthebest
nope arch is all good (I upgraded before I posted) that's the fixed version
-
icebound.dev
moparisthebest, yeah sorry I missed the constaint < 1.30.1
-
icebound.dev
1.31.0 is also good
-
icebound.dev
iirc 1.31.0 is nginx-mainline and 1.30.1 is nginx
-
icebound.dev
hence the confusion, apologies
-
AZERTY keyboard [admin@copper9.host.planetofnix.com]
> good thing OpenBSD httpd isn't affected, like usual :p hell ye ↺