DSA-6326-1

NameDSA-6326-1
Descriptionnginx - security update
SourceDebian
ReferencesCVE-2026-42946, CVE-2026-9256

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nginx (PTS)bookworm1.22.1-9+deb12u6vulnerable
bookworm (security)1.22.1-9+deb12u8fixed
trixie1.26.3-3+deb13u4vulnerable
trixie (security)1.26.3-3+deb13u6fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nginxsourcebookworm1.22.1-9+deb12u8
nginxsourcetrixie1.26.3-3+deb13u6

Search for package or bug name: Reporting problems