From nobody Fri Jun 5 13:35:18 2026 X-Original-To: freebsd-security@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4gX2W91t2xz6h4lC for ; Fri, 05 Jun 2026 13:35:33 +0000 (UTC) (envelope-from fernando.apesteguia@gmail.com) Received: from mail-ot1-f45.google.com (mail-ot1-f45.google.com [209.85.210.45]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "WR4" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4gX2W86Spwz3NTL for ; Fri, 05 Jun 2026 13:35:32 +0000 (UTC) (envelope-from fernando.apesteguia@gmail.com) Authentication-Results: mx1.freebsd.org; none Received: by mail-ot1-f45.google.com with SMTP id 46e09a7af769-7e6b5c374e5so2050845a34.0 for ; Fri, 05 Jun 2026 06:35:32 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780666531; x=1781271331; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=+WvDAKYD/jH/IZg7vXZC7KkUrI1uZv4yyOH9gSZlHZE=; b=anwpsUykcqpSAPlUfKnLCXPk6vb1aNHO/rF474buTD1nYoQybU83LbBHc5fKqEvTVs Lk65eUoxbrhTR06O7AUFecu1zUCerx1/6JbaDeU4IfzyoCe7gi4MIvY7Jl5RihtHa4Uk 2aEkejwnXvlaROTddE1AD4sxWB5mQy6bJCEzOkFFbEBUjNAPXLB7A+DeTbIwgFnJgYEY PbEQx2YmMKdWcc3wUDkbWd766jzE4o75+3DqqDyeacC2Tc3O4WiTHcFP81277hwOJTUA Ch0SkI2ZMV5lYSRWLcawY8XHzKaFneDBzPPi1H7OgNJ6otP5zgY/UiNYRaADcrz2MyoO BmyQ== X-Forwarded-Encrypted: i=1; AFNElJ8N+li5Q5tv/BVw8X4g8QHuIn9Bm/Keurc36FbclM1IMLsESIsdvEfDGKkArXIZpv+vOI6SATvy0HFCLwzHvKBv@freebsd.org X-Gm-Message-State: AOJu0YzO6JskHO+wr5LGTpDU1kMkqVIUjMsPAacVZq6CQZlnKsEgdRp5 UAXta08RUUha98TcC8hWpYbZLAu8OcyyDGHrJ6cxGigBOTH/PbknVf2aLZZQeoam X-Gm-Gg: Acq92OHzfyDxqF2JzHabr3jCUngRVQFZ1IezJ15gt0qimpRZmTIGbgSx5deHVF+BxfX 131d0RyRVjrfley6KP+REB2sy0UbDF7tesWs4aN9oYOvvR1MQXE5cRMt8+5LiRbY4gxFi3f9qwO 1+WmLXb1Wa1N18euIhUpVHe1tZtwNOHxib4BeD7uFbd5iXrBF7GOIyUrcT+8IDX+5mAAfUlazKl 4MACuRj5dbqQ8cYVljP3PGMOBpfMB4gu3660fciF8+JafElX73+Ci5JgSfw5eLKfGfB/HEpW6iE QktmvL7BDkRWboWj8HZTKNXhbFKJacrUV5Ou3P3CtZPxVqHnOsqU+ukxjZIoyBr6fj3oqkDd+rR iE8Zl6vH+s34wlWkfZsCF8R4IekhuzaCKT4tx+TMOarRC7pL+GX4a97HX9YX3Udg5KW9pK9nadU L2+hDhJXyJ1bKujS9up7ixaka1O3iUMWEH8Q7Okrzel/Iv5BiGq+IEw7AB8LyuWTNWnJEDMTXub krAff0QV+k5f17N8EE2sf5y0hFUTg== X-Received: by 2002:a05:6830:829b:b0:7dc:d7e5:8d43 with SMTP id 46e09a7af769-7e70f23c203mr1302778a34.2.1780666531381; Fri, 05 Jun 2026 06:35:31 -0700 (PDT) Received: from mail-ot1-f43.google.com (mail-ot1-f43.google.com. [209.85.210.43]) by smtp.gmail.com with ESMTPSA id 46e09a7af769-7e6e75b2017sm5629210a34.8.2026.06.05.06.35.30 for (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 05 Jun 2026 06:35:31 -0700 (PDT) Received: by mail-ot1-f43.google.com with SMTP id 46e09a7af769-7e6b5c374e5so2050823a34.0 for ; Fri, 05 Jun 2026 06:35:30 -0700 (PDT) X-Forwarded-Encrypted: i=1; AFNElJ86Lli2hopKdNW5iAe+rjRSdjcLc51MmOEm0vNz64EEnIwrsIkSjmQI5DdRewnMYYnpYup/1IFtofYHeTAvc9J1@freebsd.org X-Received: by 2002:a05:6820:2903:b0:696:8cb7:3167 with SMTP id 006d021491bc7-69e6d3866b0mr941848eaf.14.1780666530704; Fri, 05 Jun 2026 06:35:30 -0700 (PDT) List-Id: Security issues List-Archive: https://lists.freebsd.org/archives/freebsd-security List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: freebsd-security@freebsd.org Sender: owner-freebsd-security@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 References: <202606011426.651EQMeV018896@higson.cam.lispworks.com> In-Reply-To: From: =?UTF-8?Q?Fernando_Apestegu=C3=ADa?= Date: Fri, 5 Jun 2026 15:35:18 +0200 X-Gmail-Original-Message-ID: X-Gm-Features: AVHnY4LzV1TqWi_5eGYQZb7LuCALUvL5xPTTR9CJDPjo5q4s5uhNG5i4xlVcXnc Message-ID: Subject: Re: nginx-1.30.2_2,3 wrongly vulnerable to CVE-2026-9256 ? To: Arnaud de Prelle Cc: Martin Simmons , Jochen Neumeister , freebsd-security@freebsd.org Content-Type: multipart/alternative; boundary="00000000000006b5f7065381bc37" X-Spamd-Result: default: False [-4.00 / 15.00]; REPLY(-4.00)[]; TAGGED_FROM(0.00)[]; ASN(0.00)[asn:15169, ipnet:209.85.128.0/17, country:US] X-Rspamd-Queue-Id: 4gX2W86Spwz3NTL X-Spamd-Bar: ---- X-Rspamd-Pre-Result: action=no action; module=replies; Message is reply to one we originated --00000000000006b5f7065381bc37 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable El vie, 5 jun 2026, 14:47, Arnaud de Prelle escribi=C3= =B3: > Hi all, > > Thank you for your adaptations. > > Alert has now disappeared from pkg audit -F as the vuXML database now > shows : > 0.1.17,3 <=3D nginx < 1.30.2_2,3 > 1.31.0,3 <=3D nginx < 1.31.1,3 > > Kind regards, > Arnaud. > Thank you all for reporting and sorry for the mistake. > On 2026-06-01 22:42, Fernando Apestegu=C3=ADa wrote: > > Including joneum@ who maintains the port. > > > > On Mon, Jun 1, 2026 at 2:26=E2=80=AFPM Martin Simmons > > wrote: > > > >> [fernape@ added] > >> > >> >>>>> On Sun, 31 May 2026 22:01:11 +0200, Arnaud de Prelle said: > >> > > >> > Hi, > >> > > >> > As per > >> > - https://www.freshports.org/www/nginx/ and > >> > - > >> > > >> > https://vuxml.freebsd.org/freebsd/36a3131d-5600-11f1-b339-3497f65b111b.ht= ml > >> > CVE-2026-9256 should be fixed since nginx 1.30.2,3. > >> > >> The contents of this URL was stale -- the VuXML now says nginx < > >> 1.31.1,3 > >> (since yesterday), which explains why pkg audit is detecting it. > >> > >> > I'm using the latest version of nginx: > >> > # pkg info nginx | grep Version > >> > Version : 1.30.2_2,3 > >> > > >> > But pkg audit -F reports this port as vulnerable to CVE-2026-9256: > >> > # pkg audit -F > >> > vulnxml file up-to-date > >> > nginx-1.30.2_2,3 is vulnerable: > >> > nginx -- heap buffer overflow in ngx_http_rewrite_module > >> > CVE: CVE-2026-9256 > >> > WWW: > >> > > >> > https://vuxml.FreeBSD.org/freebsd/36a3131d-5600-11f1-b339-3497f65b111b.ht= ml > >> > > >> > Am I missing something ? > >> > >> The VuXML looks wrong to me now. > >> > >> nginx released both 1.30.2 and 1.31.1 to fix this CVE > >> (https://nginx.org/en/CHANGES-1.30 and https://nginx.org/en/CHANGES). > >> > >> __Martin > >> > --00000000000006b5f7065381bc37 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable


El vie, 5 jun 2026, 14:47, Arnau= d de Prelle <arnaud@pnzone.net&= gt; escribi=C3=B3:
Hi all,

Thank you for your adaptations.

Alert has now disappeared from pkg audit -F as the vuXML database now
shows :
0.1.17,3=C2=A0 =C2=A0 =C2=A0 =C2=A0 <=3D=C2=A0 =C2=A0 =C2=A0 nginx=C2=A0= =C2=A0<=C2=A0 =C2=A0 =C2=A0 =C2=A01.30.2_2,3
1.31.0,3=C2=A0 =C2=A0 =C2=A0 =C2=A0 <=3D=C2=A0 =C2=A0 =C2=A0 nginx=C2=A0= =C2=A0<=C2=A0 =C2=A0 =C2=A0 =C2=A01.31.1,3

Kind regards,
Arnaud.

Thank you all for reporting and sorry for the mistake.


On 2026-06-01 22:42, Fernando Apestegu=C3=ADa wrote:
> Including joneum@ who maintains the port.
>
> On Mon, Jun 1, 2026 at 2:26=E2=80=AFPM Martin Simmons <martin@lis= pworks.com>
> wrote:
>
>> [fernape@ added]
>>
>> >>>>> On Sun, 31 May 2026 22:01:11 +0200, Arnaud de= Prelle said:
>> >
>> > Hi,
>> >
>> > As per
>> > - https://www.freshports.org/www/nginx= / and
>> > -
>> >
>> https= ://vuxml.freebsd.org/freebsd/36a3131d-5600-11f1-b339-3497f65b111b.html<= br> >> > CVE-2026-9256 should be fixed since nginx 1.30.2,3.
>>
>> The contents of this URL was stale -- the VuXML now says nginx <= ;
>> 1.31.1,3
>> (since yesterday), which explains why pkg audit is detecting it. >>
>> > I'm using the latest version of nginx:
>> > # pkg info nginx | grep Version
>> > Version=C2=A0 =C2=A0 =C2=A0 =C2=A0 : 1.30.2_2,3
>> >
>> > But pkg audit -F reports this port as vulnerable to CVE-2026-= 9256:
>> > # pkg audit -F
>> > vulnxml file up-to-date
>> > nginx-1.30.2_2,3 is vulnerable:
>> >=C2=A0 =C2=A0 nginx -- heap buffer overflow in ngx_http_rewrit= e_module
>> >=C2=A0 =C2=A0 CVE: CVE-2026-9256
>> >=C2=A0 =C2=A0 WWW:
>> >
>> https= ://vuxml.FreeBSD.org/freebsd/36a3131d-5600-11f1-b339-3497f65b111b.html<= br> >> >
>> > Am I missing something ?
>>
>> The VuXML looks wrong to me now.
>>
>> nginx released both 1.30.2 and 1.31.1 to fix this CVE
>> (https://nginx.org/en/CHANGES-1.30 and https://nginx.org/en/CHANGES).
>>
>> __Martin
>>
--00000000000006b5f7065381bc37--