Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package nginx for openSUSE:Factory checked in at 2026-09-17 15:15:44 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/nginx (Old) and /work/SRC/openSUSE:Factory/.nginx.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "nginx" Thu Sep 17 15:15:44 2026 rev:119 rq:1378208 version:1.31.6 Changes: -------- --- /work/SRC/openSUSE:Factory/nginx/nginx.changes 2026-09-07 11:30:11.361805144 +0200 +++ /work/SRC/openSUSE:Factory/.nginx.new.383539/nginx.changes 2026-09-17 15:15:55.326163787 +0200 @@ -1,0 +2,23 @@ +Tue Sep 15 15:44:14 UTC 2026 - Marcus Rueckert <[email protected]> + +- Update to 1.31.6 (boo# 1280584) + *) Security: a heap memory buffer overflow might occur in a worker + process under certain configurations when using HTTP/3 with + OpenSSL 3.5.0 and earlier (CVE-2026-90439). + Thanks to Banny Liao. + *) Change: now the QUIC transport parameters extension received + in an SSL connection is always ignored. + *) Bugfix: binary upgrade refused to work if the control API + socket was specified and the new nginx executable was built + with the ngx_http_perl_module. + *) Bugfix: an error while evaluating a predicate in a predicate + location was ignored and the predicate was treated as false. + *) Bugfix: an error during a nested location lookup might be + ignored if locations given by regular expressions or + predicates were configured at the current level. + *) Bugfix: a segmentation fault might occur while reading + configuration if the "geo" directive with the "ranges" + parameter was used and the corresponding binary base file was + corrupted. + +------------------------------------------------------------------- Old: ---- nginx-1.31.5.tar.gz nginx-1.31.5.tar.gz.asc New: ---- nginx-1.31.6.tar.gz nginx-1.31.6.tar.gz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ nginx.spec ++++++ --- /var/tmp/diff_new_pack.XyXJjA/_old 2026-09-17 15:15:56.331205907 +0200 +++ /var/tmp/diff_new_pack.XyXJjA/_new 2026-09-17 15:15:56.333205991 +0200 @@ -24,7 +24,7 @@ %bcond_with awslc # Name: nginx -Version: 1.31.5 +Version: 1.31.6 Release: 0 Summary: A HTTP server and IMAP/POP3 proxy server License: BSD-2-Clause ++++++ nginx-1.31.5.tar.gz -> nginx-1.31.6.tar.gz ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/nginx-1.31.5/CHANGES new/nginx-1.31.6/CHANGES --- old/nginx-1.31.5/CHANGES 2026-09-02 13:48:54.000000000 +0200 +++ new/nginx-1.31.6/CHANGES 2026-09-15 14:56:25.000000000 +0200 @@ -1,4 +1,30 @@ +Changes with nginx 1.31.6 15 Sep 2026 + + *) Security: a heap memory buffer overflow might occur in a worker + process under certain configurations when using HTTP/3 with OpenSSL + 3.5.0 and earlier (CVE-2026-90439). + Thanks to Banny Liao. + + *) Change: now the QUIC transport parameters extension received in an + SSL connection is always ignored. + + *) Bugfix: binary upgrade refused to work if the control API socket was + specified and the new nginx executable was built with the + ngx_http_perl_module. + + *) Bugfix: an error while evaluating a predicate in a predicate location + was ignored and the predicate was treated as false. + + *) Bugfix: an error during a nested location lookup might be ignored if + locations given by regular expressions or predicates were configured + at the current level. + + *) Bugfix: a segmentation fault might occur while reading configuration + if the "geo" directive with the "ranges" parameter was used and the + corresponding binary base file was corrupted. + + Changes with nginx 1.31.5 02 Sep 2026 *) Feature: control API. diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/nginx-1.31.5/CHANGES.ru new/nginx-1.31.6/CHANGES.ru --- old/nginx-1.31.5/CHANGES.ru 2026-09-02 13:48:54.000000000 +0200 +++ new/nginx-1.31.6/CHANGES.ru 2026-09-15 14:56:24.000000000 +0200 @@ -1,4 +1,30 @@ +Изменения в nginx 1.31.6 15.09.2026 + + *) Безопасность: при использовании HTTP/3 с OpenSSL 3.5.0 и более + ранними версиями в определённых конфигурациях могло произойти + переполнение буфера в рабочем процессе (CVE-2026-90439). + Спасибо Banny Liao. + + *) Изменение: теперь расширение QUIC transport parameters, полученное в + SSL-соединении, всегда игнорируется. + + *) Исправление: процедура обновления исполняемого файла не работала, + если был указан сокет control API и новый исполняемый файл nginx был + собран с модулем ngx_http_perl_module. + + *) Исправление: ошибка при вычислении предиката в предикатном location'е + игнорировалась, и такой предикат считался ложным. + + *) Исправление: ошибка при поиске вложенного location'а могла + игнорироваться, если на текущем уровне были настроены location'ы, + заданные регулярными выражениями или предикатами. + + *) Исправление: при чтении конфигурации мог произойти segmentation + fault, если использовалась директива geo с параметром ranges и + соответствующий файл бинарной базы был повреждён. + + Изменения в nginx 1.31.5 02.09.2026 *) Добавление: control API. diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/nginx-1.31.5/man/nginx.8 new/nginx-1.31.6/man/nginx.8 --- old/nginx-1.31.5/man/nginx.8 2026-09-02 13:17:13.000000000 +0200 +++ new/nginx-1.31.6/man/nginx.8 2026-09-15 14:54:15.000000000 +0200 @@ -25,7 +25,7 @@ .\" SUCH DAMAGE. .\" .\" -.Dd January 21, 2026 +.Dd September 4, 2026 .Dt NGINX 8 .Os .Sh NAME @@ -37,6 +37,7 @@ .Op Fl c Ar file .Op Fl e Ar file .Op Fl g Ar directives +.Op Fl l Ar address .Op Fl p Ar prefix .Op Fl s Ar signal .Sh DESCRIPTION @@ -66,6 +67,11 @@ See .Sx EXAMPLES for details. +.It Fl l Ar address +Set a control socket listen address. +See +.Sx CONTROL SOCKET +for details. .It Fl p Ar prefix Set the prefix path. The default value is @@ -165,6 +171,27 @@ debug_connection 127.0.0.1; } .Ed +.Sh CONTROL SOCKET +To enable a control socket, reconfigure +.Nm +to build with control API: +.Pp +.Dl "./configure --with-control-api ..." +.Pp +and then set the control socket listen address, for example: +.Bd -literal -offset indent +nginx -c ~/mynginx.conf -l 127.0.0.1:8888 +.Ed +.Pp +IPv6 addresses should be enclosed in square brackets: +.Bd -literal -offset indent +nginx -c ~/mynginx.conf -l [::1]:8888 +.Ed +.Pp +It is also possible to set a UNIX-domain socket: +.Bd -literal -offset indent +nginx -c ~/mynginx.conf -l unix:/path/to/socket +.Ed .Sh ENVIRONMENT The .Ev NGINX @@ -197,9 +224,6 @@ .\"Pp Documentation at .Pa http://nginx.org/en/docs/ . -.Pp -For questions and technical support, please refer to -.Pa http://nginx.org/en/support.html . .Sh HISTORY Development of .Nm diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/nginx-1.31.5/src/core/nginx.c new/nginx-1.31.6/src/core/nginx.c --- old/nginx-1.31.5/src/core/nginx.c 2026-09-02 13:17:13.000000000 +0200 +++ new/nginx-1.31.6/src/core/nginx.c 2026-09-15 14:54:15.000000000 +0200 @@ -289,6 +289,10 @@ return 1; } +#if (NGX_CONTROL_API) + ngx_control_preinit(); +#endif + if (ngx_preinit_modules() != NGX_OK) { return 1; } diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/nginx-1.31.5/src/core/nginx.h new/nginx-1.31.6/src/core/nginx.h --- old/nginx-1.31.5/src/core/nginx.h 2026-09-02 13:17:13.000000000 +0200 +++ new/nginx-1.31.6/src/core/nginx.h 2026-09-15 14:54:15.000000000 +0200 @@ -9,8 +9,8 @@ #define _NGINX_H_INCLUDED_ -#define nginx_version 1031005 -#define NGINX_VERSION "1.31.5" +#define nginx_version 1031006 +#define NGINX_VERSION "1.31.6" #define NGINX_VER "nginx/" NGINX_VERSION #ifdef NGX_BUILD diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/nginx-1.31.5/src/event/quic/ngx_event_quic_openssl_compat.c new/nginx-1.31.6/src/event/quic/ngx_event_quic_openssl_compat.c --- old/nginx-1.31.5/src/event/quic/ngx_event_quic_openssl_compat.c 2026-09-02 13:17:13.000000000 +0200 +++ new/nginx-1.31.6/src/event/quic/ngx_event_quic_openssl_compat.c 2026-09-15 14:54:15.000000000 +0200 @@ -70,11 +70,16 @@ ngx_str_t *res); -ngx_int_t -ngx_quic_compat_init(ngx_conf_t *cf, SSL_CTX *ctx) +void +ngx_quic_compat_keylog_init(SSL_CTX *ctx) { SSL_CTX_set_keylog_callback(ctx, ngx_quic_compat_keylog_callback); +} + +ngx_int_t +ngx_quic_compat_ext_init(ngx_conf_t *cf, SSL_CTX *ctx) +{ if (SSL_CTX_has_client_custom_ext(ctx, NGX_QUIC_COMPAT_SSL_TP_EXT)) { return NGX_OK; } @@ -341,7 +346,7 @@ c = ngx_ssl_get_connection(ssl); if (c->type != SOCK_DGRAM) { - return 0; + return 1; } ngx_log_debug0(NGX_LOG_DEBUG_EVENT, c->log, 0, diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/nginx-1.31.5/src/event/quic/ngx_event_quic_openssl_compat.h new/nginx-1.31.6/src/event/quic/ngx_event_quic_openssl_compat.h --- old/nginx-1.31.5/src/event/quic/ngx_event_quic_openssl_compat.h 2026-09-02 13:17:13.000000000 +0200 +++ new/nginx-1.31.6/src/event/quic/ngx_event_quic_openssl_compat.h 2026-09-15 14:54:15.000000000 +0200 @@ -38,7 +38,8 @@ } SSL_QUIC_METHOD; -ngx_int_t ngx_quic_compat_init(ngx_conf_t *cf, SSL_CTX *ctx); +void ngx_quic_compat_keylog_init(SSL_CTX *ctx); +ngx_int_t ngx_quic_compat_ext_init(ngx_conf_t *cf, SSL_CTX *ctx); int SSL_set_quic_method(SSL *ssl, const SSL_QUIC_METHOD *quic_method); int SSL_provide_quic_data(SSL *ssl, enum ssl_encryption_level_t level, diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/nginx-1.31.5/src/http/modules/ngx_http_geo_module.c new/nginx-1.31.6/src/http/modules/ngx_http_geo_module.c --- old/nginx-1.31.5/src/http/modules/ngx_http_geo_module.c 2026-09-02 13:17:13.000000000 +0200 +++ new/nginx-1.31.6/src/http/modules/ngx_http_geo_module.c 2026-09-15 14:54:15.000000000 +0200 @@ -1423,7 +1423,6 @@ time_t mtime; size_t size, len; ssize_t n; - uint32_t crc32; ngx_err_t err; ngx_int_t rc; ngx_uint_t i; @@ -1518,24 +1517,45 @@ goto failed; } - ngx_crc32_init(crc32); + /* + * the base is walked below without bounds checking, so make sure + * it is intact first: the checksum in the header is computed over + * the entire body, which the walk covers contiguously + */ + + if (size < sizeof(ngx_http_geo_header_t) + + sizeof(ngx_http_variable_value_t) + + 0x10000 * sizeof(ngx_http_geo_range_t *)) + { + ngx_conf_log_error(NGX_LOG_WARN, cf, 0, + "truncated binary geo range base \"%s\"", + name->data); + goto failed; + } + + if (ngx_crc32_long(base + sizeof(ngx_http_geo_header_t), + size - sizeof(ngx_http_geo_header_t)) + != header->crc32) + { + ngx_conf_log_error(NGX_LOG_WARN, cf, 0, + "CRC32 mismatch in binary geo range base \"%s\"", + name->data); + goto failed; + } vv = (ngx_http_variable_value_t *) (base + sizeof(ngx_http_geo_header_t)); while (vv->data) { len = ngx_align(sizeof(ngx_http_variable_value_t) + vv->len, sizeof(void *)); - ngx_crc32_update(&crc32, (u_char *) vv, len); vv->data += (size_t) base; vv = (ngx_http_variable_value_t *) ((u_char *) vv + len); } - ngx_crc32_update(&crc32, (u_char *) vv, sizeof(ngx_http_variable_value_t)); vv++; ranges = (ngx_http_geo_range_t **) vv; for (i = 0; i < 0x10000; i++) { - ngx_crc32_update(&crc32, (u_char *) &ranges[i], sizeof(void *)); if (ranges[i]) { ranges[i] = (ngx_http_geo_range_t *) ((u_char *) ranges[i] + (size_t) base); @@ -1546,24 +1566,13 @@ while ((u_char *) range < base + size) { while (range->value) { - ngx_crc32_update(&crc32, (u_char *) range, - sizeof(ngx_http_geo_range_t)); range->value = (ngx_http_variable_value_t *) ((u_char *) range->value + (size_t) base); range++; } - ngx_crc32_update(&crc32, (u_char *) range, sizeof(void *)); range = (ngx_http_geo_range_t *) ((u_char *) range + sizeof(void *)); } - ngx_crc32_final(crc32); - - if (crc32 != header->crc32) { - ngx_conf_log_error(NGX_LOG_WARN, cf, 0, - "CRC32 mismatch in binary geo range base \"%s\"", name->data); - goto failed; - } - ngx_conf_log_error(NGX_LOG_NOTICE, cf, 0, "using binary geo range base \"%s\"", name->data); diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/nginx-1.31.5/src/http/modules/ngx_http_ssl_module.c new/nginx-1.31.6/src/http/modules/ngx_http_ssl_module.c --- old/nginx-1.31.5/src/http/modules/ngx_http_ssl_module.c 2026-09-02 13:17:13.000000000 +0200 +++ new/nginx-1.31.6/src/http/modules/ngx_http_ssl_module.c 2026-09-15 14:54:15.000000000 +0200 @@ -1379,6 +1379,9 @@ ngx_http_ssl_init(ngx_conf_t *cf) { ngx_uint_t a, p, s; +#if (NGX_QUIC_OPENSSL_COMPAT) + ngx_uint_t compat; +#endif const char *name; ngx_http_conf_addr_t *addr; ngx_http_conf_port_t *port; @@ -1423,6 +1426,25 @@ return NGX_OK; } +#if (NGX_QUIC_OPENSSL_COMPAT) + + compat = 0; + + port = cmcf->ports->elts; + for (p = 0; p < cmcf->ports->nelts && !compat; p++) { + + addr = port[p].addrs.elts; + for (a = 0; a < port[p].addrs.nelts; a++) { + + if (addr[a].opt.quic) { + compat = 1; + break; + } + } + } + +#endif + port = cmcf->ports->elts; for (p = 0; p < cmcf->ports->nelts; p++) { @@ -1433,15 +1455,17 @@ continue; } - if (addr[a].opt.quic) { - name = "quic"; - #if (NGX_QUIC_OPENSSL_COMPAT) + if (compat) { if (ngx_http_ssl_quic_compat_init(cf, &addr[a]) != NGX_OK) { return NGX_ERROR; } + } #endif + if (addr[a].opt.quic) { + name = "quic"; + } else { name = "ssl"; } @@ -1514,9 +1538,13 @@ sscf = cscf->ctx->srv_conf[ngx_http_ssl_module.ctx_index]; if (sscf->certificates || sscf->reject_handshake) { - if (ngx_quic_compat_init(cf, sscf->ssl.ctx) != NGX_OK) { + if (ngx_quic_compat_ext_init(cf, sscf->ssl.ctx) != NGX_OK) { return NGX_ERROR; } + + if (addr->opt.quic) { + ngx_quic_compat_keylog_init(sscf->ssl.ctx); + } } } diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/nginx-1.31.5/src/http/ngx_http_core_module.c new/nginx-1.31.6/src/http/ngx_http_core_module.c --- old/nginx-1.31.5/src/http/ngx_http_core_module.c 2026-09-02 13:17:13.000000000 +0200 +++ new/nginx-1.31.6/src/http/ngx_http_core_module.c 2026-09-15 14:54:15.000000000 +0200 @@ -1470,7 +1470,7 @@ rc = ngx_http_core_find_location(r); } - if (rc == NGX_OK || rc == NGX_DONE) { + if (rc == NGX_OK || rc == NGX_DONE || rc == NGX_ERROR) { return rc; } @@ -1514,8 +1514,11 @@ "test location: \"%V\"", &(*clcfp)->name); vv = ngx_http_get_flushed_variable(r, (*clcfp)->predicate - 1); + if (vv == NULL) { + return NGX_ERROR; + } - if (vv && vv->len && (vv->len != 1 || vv->data[0] != '0')) { + if (vv->len && (vv->len != 1 || vv->data[0] != '0')) { r->loc_conf = (*clcfp)->loc_conf; /* look up nested locations */ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/nginx-1.31.5/src/os/unix/ngx_control.c new/nginx-1.31.6/src/os/unix/ngx_control.c --- old/nginx-1.31.5/src/os/unix/ngx_control.c 2026-09-02 13:17:13.000000000 +0200 +++ new/nginx-1.31.6/src/os/unix/ngx_control.c 2026-09-15 14:54:15.000000000 +0200 @@ -77,6 +77,7 @@ static ngx_uint_t ngx_control_pollfd_n; static char ngx_control_unix_path[NGX_UNIX_ADDRSTRLEN]; static ngx_uint_t ngx_control_inherited; +static u_char *ngx_control_env; ngx_uint_t ngx_control_api_enabled; @@ -131,6 +132,18 @@ }; +void +ngx_control_preinit(void) +{ + /* + * the variable is read before ngx_init_cycle(), which may replace + * the environment while parsing configuration + */ + + ngx_control_env = (u_char *) getenv(NGX_CTRL_ENV); +} + + ngx_int_t ngx_control_init(u_char *addr) { @@ -382,7 +395,7 @@ u_char *env; ngx_fd_t fd; - env = (u_char *) getenv(NGX_CTRL_ENV); + env = ngx_control_env; if (env == NULL) { return NGX_DECLINED; } diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/nginx-1.31.5/src/os/unix/ngx_control.h new/nginx-1.31.6/src/os/unix/ngx_control.h --- old/nginx-1.31.5/src/os/unix/ngx_control.h 2026-09-02 13:17:13.000000000 +0200 +++ new/nginx-1.31.6/src/os/unix/ngx_control.h 2026-09-15 14:54:15.000000000 +0200 @@ -12,6 +12,7 @@ #include <ngx_core.h> +void ngx_control_preinit(void); ngx_int_t ngx_control_init(u_char *addr); void ngx_control_uninit(void); void ngx_control_close_sockets(void); diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/nginx-1.31.5/src/stream/ngx_stream_geo_module.c new/nginx-1.31.6/src/stream/ngx_stream_geo_module.c --- old/nginx-1.31.5/src/stream/ngx_stream_geo_module.c 2026-09-02 13:17:13.000000000 +0200 +++ new/nginx-1.31.6/src/stream/ngx_stream_geo_module.c 2026-09-15 14:54:15.000000000 +0200 @@ -1349,7 +1349,6 @@ time_t mtime; size_t size, len; ssize_t n; - uint32_t crc32; ngx_err_t err; ngx_int_t rc; ngx_uint_t i; @@ -1444,7 +1443,31 @@ goto failed; } - ngx_crc32_init(crc32); + /* + * the base is walked below without bounds checking, so make sure + * it is intact first: the checksum in the header is computed over + * the entire body, which the walk covers contiguously + */ + + if (size < sizeof(ngx_stream_geo_header_t) + + sizeof(ngx_stream_variable_value_t) + + 0x10000 * sizeof(ngx_stream_geo_range_t *)) + { + ngx_conf_log_error(NGX_LOG_WARN, cf, 0, + "truncated binary geo range base \"%s\"", + name->data); + goto failed; + } + + if (ngx_crc32_long(base + sizeof(ngx_stream_geo_header_t), + size - sizeof(ngx_stream_geo_header_t)) + != header->crc32) + { + ngx_conf_log_error(NGX_LOG_WARN, cf, 0, + "CRC32 mismatch in binary geo range base \"%s\"", + name->data); + goto failed; + } vv = (ngx_stream_variable_value_t *) (base + sizeof(ngx_stream_geo_header_t)); @@ -1452,18 +1475,14 @@ while (vv->data) { len = ngx_align(sizeof(ngx_stream_variable_value_t) + vv->len, sizeof(void *)); - ngx_crc32_update(&crc32, (u_char *) vv, len); vv->data += (size_t) base; vv = (ngx_stream_variable_value_t *) ((u_char *) vv + len); } - ngx_crc32_update(&crc32, (u_char *) vv, - sizeof(ngx_stream_variable_value_t)); vv++; ranges = (ngx_stream_geo_range_t **) vv; for (i = 0; i < 0x10000; i++) { - ngx_crc32_update(&crc32, (u_char *) &ranges[i], sizeof(void *)); if (ranges[i]) { ranges[i] = (ngx_stream_geo_range_t *) ((u_char *) ranges[i] + (size_t) base); @@ -1474,24 +1493,13 @@ while ((u_char *) range < base + size) { while (range->value) { - ngx_crc32_update(&crc32, (u_char *) range, - sizeof(ngx_stream_geo_range_t)); range->value = (ngx_stream_variable_value_t *) ((u_char *) range->value + (size_t) base); range++; } - ngx_crc32_update(&crc32, (u_char *) range, sizeof(void *)); range = (ngx_stream_geo_range_t *) ((u_char *) range + sizeof(void *)); } - ngx_crc32_final(crc32); - - if (crc32 != header->crc32) { - ngx_conf_log_error(NGX_LOG_WARN, cf, 0, - "CRC32 mismatch in binary geo range base \"%s\"", name->data); - goto failed; - } - ngx_conf_log_error(NGX_LOG_NOTICE, cf, 0, "using binary geo range base \"%s\"", name->data);
