openSUSE: 2025:0283-1 important: nginx Advisory Security Update
Description
This update for nginx fixes the following issues: * CVE-2023-44487: Mitigate HTTP/2 Rapid Reset Attack (bsc#1216171) * CVE-2024-7347: Fixed worker crashes on special crafted mp4 files containing invalid chunk information (bsc#1229155)
Patch
## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-283=1 openSUSE-SLE-15.6-2025-283=1 * Server Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP6-2025-283=1
Package List
* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * nginx-debugsource-1.21.5-150600.10.3.1 * nginx-debuginfo-1.21.5-150600.10.3.1 * nginx-1.21.5-150600.10.3.1 * openSUSE Leap 15.6 (noarch) * nginx-source-1.21.5-150600.10.3.1 * Server Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * nginx-debugsource-1.21.5-150600.10.3.1 * nginx-debuginfo-1.21.5-150600.10.3.1 * nginx-1.21.5-150600.10.3.1 * Server Applications Module 15-SP6 (noarch) * nginx-source-1.21.5-150600.10.3.1
References
* bsc#1216171 * bsc#1229155 ## References: * https://www.suse.com/security/cve/CVE-2023-44487.html * https://www.suse.com/security/cve/CVE-2024-7347.html * https://bugzilla.suse.com/show_bug.cgi?id=1216171 * https://bugzilla.suse.com/show_bug.cgi?id=1229155