Skip to content

update nginx to 1.31.6 to fix libc security vulnerability - #9188

Merged
klesh merged 1 commit into
apache:mainfrom
blueelvis:patch-1
Oct 4, 2026
Merged

klesh merged 1 commit into
apache:mainfrom
blueelvis:patch-1

Conversation

@blueelvis

@blueelvis blueelvis commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Pre Checklist

Please complete ALL items in this checklist, and remove before submitting

  • I have read through the Contributing Documentation.
  • I have added relevant tests.
  • I have added relevant documentation.
  • I will add labels to the PR, such as pr-type/bug-fix, pr-type/feature-development, etc.

Summary

Update to the latest nginx-unprivileged image to resolve the following -

  • libc6 -- Installed (2.41-12) -- Fixed in (2.41-12+deb13u4) -- CVE (CVE-2026-0915)
  • libc-bin -- Installed (2.41-12) -- Fixed in (2.41-12+deb13u4) -- CVE (CVE-2026-4046)

I have verified and the latest 1.31.6 image has the fixed version.

@klesh klesh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@klesh
klesh merged commit 7899890 into apache:main Oct 4, 2026
7 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants