PT-2022-5184 · Nginx+7 · Nginx Open Source Subscription+10

Published

2022-10-19

·

Updated

2026-04-21

·

CVE-2022-41742

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions NGINX Open Source versions 1.23.2 and earlier, excluding version 1.22.1 and later NGINX Open Source versions 1.22.1 and earlier NGINX Open Source Subscription before versions R2 P1 and R1 P1 NGINX Plus before versions R27 P1 and R26 P1
Description The issue affects NGINX products built with the module ngx http mp4 module when the mp4 directive is used in the configuration file. A local attacker might cause a worker process crash or result in worker process memory disclosure by using a specially crafted audio or video file. The attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx http mp4 module. This might allow an attacker to disclose protected information or cause a denial of service.
Recommendations For NGINX Open Source versions 1.23.2 and earlier, excluding version 1.22.1 and later: Update to version 1.23.2 or later. For NGINX Open Source versions 1.22.1 and earlier: Update to version 1.22.1 or later. For NGINX Open Source Subscription before versions R2 P1 and R1 P1: Update to version R2 P1 or R1 P1 or later. For NGINX Plus before versions R27 P1 and R26 P1: Update to version R27 P1 or R26 P1 or later. As a temporary workaround, consider disabling the ngx http mp4 module module until a patch is available. Restrict access to the mp4 directive in the configuration file to minimize the risk of exploitation. Avoid using the mp4 directive in the configuration file until the issue is resolved.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:7402
ALT-PU-2022-2896
ALT-PU-2022-2933
ALT-PU-2022-2945
ALT-PU-2022-2967
AZL-11321
BDU:2022-06441
BIT-NGINX-2022-41742
BIT-NGINX-INGRESS-CONTROLLER-2022-41742
CLEANSTART-2026-AF45008
CLEANSTART-2026-BA37192
CLEANSTART-2026-MQ02912
CLEANSTART-2026-XB16901
CLEANSTART-2026-ZN32454
CLEANSTART-2026-ZT77083
CVE-2022-41742
DLA-3203-1
DSA-5281-1
INFSA-2025_7402
MGASA-2022-0398
OESA-2022-2023
OPENSUSE-SU-2023_0205-1
OPENSUSE-SU-2023_0212-1
RHSA-2025:7402
RHSA-2025:7546
RHSA-2025:7619
RHSA-2025_7402
ROSA-SA-2025-2895
SUSE-SU-2023:0205-1
SUSE-SU-2023:0210-1
SUSE-SU-2023:0212-1
SUSE-SU-2023:0293-1
USN-5722-1

Affected Products

Alt Linux
Almalinux
Linuxmint
Nginx Open Source
Nginx Open Source Subscription
Nginx Plus
Nginx
Red Hat
Rocky Linux
Suse
Ubuntu