VDB
ALSA-2025%3A7402
ALSA-2025%3A7402
PUBLISHED
nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage. Security Fix(es): * nginx: Memory corruption in the ngx_http_mp4_module (CVE-2022-41741) * nginx: Memory disclosure in the ngx_http_mp4_module (CVE-2022-41742) * nginx: specially crafted MP4 file may cause denial of service (CVE-2024-7347) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| AlmaLinux:9 | nginx-mod-http-perl | 0, 0 |
| AlmaLinux:9 | nginx-core | 0, 0 |
| AlmaLinux:9 | nginx-mod-stream | 0, 0 |
| AlmaLinux:9 | nginx-mod-devel | 0, 0 |
| AlmaLinux:9 | nginx-mod-http-image-filter | 0, 0 |
| AlmaLinux:9 | nginx-all-modules | 0, 0 |
| SAP | concur | |
| AlmaLinux:9 | nginx-mod-mail | 0, 0 |
| AlmaLinux:9 | nginx-mod-http-xslt-filter | 0, 0 |
| AlmaLinux:9 | nginx | 0, 0 |
| AlmaLinux:9 | nginx-filesystem | 0, 0 |
Timeline
- May 13, 2025 CVE Published
- Feb 4, 2026 CVE Updated
- Mar 6, 2026 Distribution Patch
- Mar 6, 2026 Distribution Patch
- Mar 6, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2025:7402 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2022-41741 third-party-advisory
- https://access.redhat.com/security/cve/CVE-2022-41742 third-party-advisory
- https://access.redhat.com/security/cve/CVE-2024-7347 third-party-advisory
- https://bugzilla.redhat.com/2141495 third-party-advisory
- https://bugzilla.redhat.com/2141496 third-party-advisory
- https://errata.almalinux.org/9/ALSA-2025-7402.html vendor-advisory