Elektrine lite

← Feed

@sternecker@infosec.exchange

Post #4059212

2026-07-16 10:59 UTC

A few things to share, nginx: CVE-2026-42533 dropped yesterday 2026-07-15. It is fixed in nginx 1.31.3, also released yesterday. CVSS 8.1 or 9.2 depending on the nginx version. It's a heap buffer overflow in the map directive when regex... regardless, it is unauthenticated, needs a custom HTTP request, can crash it or lead to code execution if Address space layout randomization (ASLR) is disabled, or bypassed. Don't disable memory randomization. Not sure how to bypass ASLR, I'll have to look into that. glibc CVE-2026-5450 originally disclosed 2026-04-20 so it's "not new." What's new is the SSVC exploitation flag flipping to "poc" within the last 21 days meaning a proof-of-concept surfaced recently for an April CVE, which is the "weaponized old CVE" pattern we see regularly. No vendor patch exists? Maybe i'm missing it. CVSS 9.8, scanf %mc off-by-one heap overflow with an explicit width >1024... real-world exposure is low even with a PoC out. Debian 13.6 was released 2026-07-11. It's a point release, bundled a ton of security advisories including and an expired Secure Boot CA fix. It's the routine patch cycle. Make it so. #minimalist #Linux #Selfhosting #selfhosted #selfhost #InfoSec #Exploit

Replies (0)

No replies.