[Pkg-nginx-maintainers] nginx 1.26.0-2

Jan Mojzis jan.mojzis at gmail.com
Mon Aug 19 16:44:25 BST 2024


Hi,

We have new Debian version 1.26.0-2 ready
in which:
-  backported fixes from Nginx 1.26.1/1.26.2.
  - from 1.26.1 (CVE-2024-32760, CVE-2024-31079, CVE-2024-35200, CVE-2024-34161)
  - from 1.26.2 (CVE-2024-7347)
- enabled HTTP/3 protocol
- updated nginx.conf default options for current security practices and standards

Full changelog here:
https://salsa.debian.org/nginx-team/nginx/-/blob/main/debian/changelog

Note:
we do not release a version derived from the latest upstream nginx 1.26.2-1,
because it would mean changing the ABI and the need to recompile all the 3th party modules.
Instead we backported the patches and raised the debian version to 2 (1.26.0-2).

I'm planing upload 1.26.0-2 tomorrow (20.8.2024) to the unstable.

Jan


More information about the Pkg-nginx-maintainers mailing list