diff options
| author | Thomas Gerbet <thomas@gerbet.me> | 2024-05-31 11:30:28 +0200 |
|---|---|---|
| committer | Thomas Gerbet <thomas@gerbet.me> | 2024-05-31 11:30:28 +0200 |
| commit | 25e4a15f2ade9d8fb33a97603cd99652e6870d42 (patch) | |
| tree | d9222a2b9c4f64ceacb70e7495cc0416350e6730 /pkgs/development/python-modules/rangehttpserver | |
| parent | c7e65c09b0a9f2fa04f24fcc2d2654081bd339a7 (diff) | |
nginx: 1.26.0 -> 1.26.1
Fixes CVE-2024-32760, CVE-2024-31079, CVE-2024-35200 and CVE-2024-34161.
Note that the `nginxQuic` derivation rely on `nginxMainline`.
Changes:
```
Changes with nginx 1.26.1 29 May 2024
*) Security: when using HTTP/3, processing of a specially crafted QUIC
session might cause a worker process crash, worker process memory
disclosure on systems with MTU larger than 4096 bytes, or might have
potential other impact (CVE-2024-32760, CVE-2024-31079,
CVE-2024-35200, CVE-2024-34161).
Thanks to Nils Bars of CISPA.
*) Bugfix: reduced memory consumption for long-lived requests if "gzip",
"gunzip", "ssi", "sub_filter", or "grpc_pass" directives are used.
*) Bugfix: nginx could not be built by gcc 14 if the --with-atomic
option was used.
Thanks to Edgar Bonet.
*) Bugfix: in HTTP/3.
```
Diffstat (limited to 'pkgs/development/python-modules/rangehttpserver')
0 files changed, 0 insertions, 0 deletions
