PT-2024-5858 · Nginx+9 · Nginx Open Source+11

Nils Bars

·

Published

2024-08-14

·

Updated

2026-04-21

·

CVE-2024-7347

CVSS v4.0

5.7

Medium

VectorAV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions NGINX Open Source and NGINX Plus versions prior to 1.26.2 NGINX Open Source and NGINX Plus versions prior to 1.27.1
Description The issue is related to a buffer overread vulnerability in the ngx http mp4 module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx http mp4 module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx http mp4 module.
Recommendations For NGINX Open Source and NGINX Plus versions prior to 1.26.2, update to version 1.26.2 or later. For NGINX Open Source and NGINX Plus versions prior to 1.27.1, update to version 1.27.1 or later. As a temporary workaround, consider disabling the ngx http mp4 module until a patch is available. Restrict access to the mp4 directive in the configuration file to minimize the risk of exploitation. Avoid using specially crafted mp4 files that can trigger the processing of the ngx http mp4 module until the issue is resolved.

Fix

Buffer Over-read

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:3261
ALSA-2025:3262
ALSA-2025:7402
ALT-PU-2024-11335
ALT-PU-2024-11582
ALT-PU-2024-12155
ALT-PU-2024-12157
ALT-PU-2024-12161
AZL-47781
AZL-47789
BDU:2024-06605
BIT-NGINX-2024-7347
BIT-NGINX-GATEWAY-2024-7347
CLEANSTART-2026-AF45008
CLEANSTART-2026-BA37192
CLEANSTART-2026-MQ02912
CLEANSTART-2026-XB16901
CLEANSTART-2026-ZN32454
CLEANSTART-2026-ZT77083
CVE-2024-7347
DLA-4091-1
ECHO-8390-88AC-B8EC
INFSA-2025_3261
INFSA-2025_3262
INFSA-2025_7402
MGASA-2024-0286
OESA-2024-2065
OESA-2024-2086
OESA-2024-2087
OESA-2024-2088
OESA-2024-2089
OPENSUSE-SU-2024:14271-1
OPENSUSE-SU-2025_0282-1
OPENSUSE-SU-2025_0283-1
RHSA-2025:3261
RHSA-2025:3262
RHSA-2025:7402
RHSA-2025:7542
RHSA-2025:7546
RHSA-2025:7548
RHSA-2025:7549
RHSA-2025:7619
RHSA-2025_3261
RHSA-2025_3262
RHSA-2025_7402
ROSA-SA-2025-2895
SUSE-SU-2025:0282-1
SUSE-SU-2025:0283-1
SUSE-SU-2025_0282-1
SUSE-SU-2025_0283-1
USN-7014-1
USN-7014-2
USN-7014-3

Affected Products

Alt Linux
Almalinux
Debian
Linuxmint
Nginx Open Source
Nginx Plus
Nginx
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu