VDB

ALSA-2025%3A7402

ALSA-2025%3A7402 PUBLISHED

nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage. Security Fix(es): * nginx: Memory corruption in the ngx_http_mp4_module (CVE-2022-41741) * nginx: Memory disclosure in the ngx_http_mp4_module (CVE-2022-41742) * nginx: specially crafted MP4 file may cause denial of service (CVE-2024-7347) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected Products

VendorProductVersions
AlmaLinux:9nginx-mod-http-perl0, 0
AlmaLinux:9nginx-core0, 0
AlmaLinux:9nginx-mod-stream0, 0
AlmaLinux:9nginx-mod-devel0, 0
AlmaLinux:9nginx-mod-http-image-filter0, 0
AlmaLinux:9nginx-all-modules0, 0
SAPconcur
AlmaLinux:9nginx-mod-mail0, 0
AlmaLinux:9nginx-mod-http-xslt-filter0, 0
AlmaLinux:9nginx0, 0
AlmaLinux:9nginx-filesystem0, 0

Timeline

  • May 13, 2025 CVE Published
  • Feb 4, 2026 CVE Updated
  • Mar 6, 2026 Distribution Patch
  • Mar 6, 2026 Distribution Patch
  • Mar 6, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›