PT-2022-5185 · Nginx+7 · Nginx Open Source Subscription+10

Published

2022-10-19

·

Updated

2026-04-21

·

CVE-2022-41741

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NGINX Open Source versions 1.23.2 and 1.22.1 and earlier NGINX Open Source Subscription versions R2 P1 and R1 P1 and earlier NGINX Plus versions R27 P1 and R26 P1 and earlier
Description The issue is related to a buffer-over-read vulnerability in the ngx http mp4 module of NGINX products. This vulnerability might allow a local attacker to corrupt NGINX worker memory, resulting in its termination or potential other impact, by using a specially crafted audio or video file. The attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the ngx http mp4 module, and the mp4 directive is used in the configuration file.
Recommendations For NGINX Open Source versions 1.23.2 and 1.22.1 and earlier, update to version 1.23.2 or 1.22.1 or later. For NGINX Open Source Subscription versions R2 P1 and R1 P1 and earlier, update to version R2 P1 or R1 P1 or later. For NGINX Plus versions R27 P1 and R26 P1 and earlier, update to version R27 P1 or R26 P1 or later. As a temporary workaround, consider disabling the ngx http mp4 module until a patch is available. Restrict access to the mp4 directive in the configuration file to minimize the risk of exploitation. Avoid using the ngx http mp4 module to process audio or video files until the issue is resolved.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:7402
ALT-PU-2022-2896
ALT-PU-2022-2933
ALT-PU-2022-2945
ALT-PU-2022-2967
AZL-11320
BDU:2022-06442
BIT-NGINX-2022-41741
BIT-NGINX-INGRESS-CONTROLLER-2022-41741
CLEANSTART-2026-AF45008
CLEANSTART-2026-BA37192
CLEANSTART-2026-MQ02912
CLEANSTART-2026-XB16901
CLEANSTART-2026-ZN32454
CLEANSTART-2026-ZT77083
CVE-2022-41741
DLA-3203-1
DSA-5281-1
INFSA-2025_7402
MGASA-2022-0398
OESA-2022-2023
OPENSUSE-SU-2023_0205-1
OPENSUSE-SU-2023_0212-1
OPENSUSE-SU-2024:12433-1
RHSA-2025:7402
RHSA-2025:7546
RHSA-2025:7619
RHSA-2025_7402
ROSA-SA-2025-2895
SUSE-SU-2023:0205-1
SUSE-SU-2023:0210-1
SUSE-SU-2023:0212-1
SUSE-SU-2023:0293-1
SUSE-SU-2023_0205-1
SUSE-SU-2023_0210-1
SUSE-SU-2023_0212-1
SUSE-SU-2023_0293-1
USN-5722-1

Affected Products

Alt Linux
Almalinux
Linuxmint
Nginx Open Source
Nginx Open Source Subscription
Nginx Plus
Nginx
Red Hat
Rocky Linux
Suse
Ubuntu