OESA-2025-1134

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2025-1134
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2025-1134.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2025-1134
Upstream
Published
2025-02-14T12:13:11Z
Modified
2025-08-12T05:49:20.728737Z
Summary
nginx security update
Details

NGINX is a free, open-source, high-performance HTTP server and reverse proxy, as well as an IMAP/POP3 proxy server.

Security Fix(es):

When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS Session Tickets https://nginx.org/en/docs/http/ngxhttpsslmodule.html#sslsessionticketkey are used and/or the SSL session cache https://nginx.org/en/docs/http/ngxhttpsslmodule.html#sslsession_cache are used in the default server and the default server is performing client certificate authentication.  

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.(CVE-2025-23419)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:24.03-LTS / nginx

Package

Name
nginx
Purl
pkg:rpm/openEuler/nginx&distro=openEuler-24.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.24.0-4.oe2403sp1

Ecosystem specific

{
    "src": [
        "nginx-1.24.0-3.oe2403.src.rpm",
        "compat-nginx-1.24.0-4.oe2403sp1.src.rpm",
        "nginx-1.24.0-4.oe2403sp1.src.rpm"
    ],
    "noarch": [
        "nginx-all-modules-1.24.0-3.oe2403.noarch.rpm",
        "nginx-filesystem-1.24.0-3.oe2403.noarch.rpm",
        "nginx-help-1.24.0-3.oe2403.noarch.rpm",
        "compat-nginx-all-modules-1.24.0-4.oe2403sp1.noarch.rpm",
        "compat-nginx-filesystem-1.24.0-4.oe2403sp1.noarch.rpm",
        "compat-nginx-help-1.24.0-4.oe2403sp1.noarch.rpm",
        "nginx-all-modules-1.24.0-4.oe2403sp1.noarch.rpm",
        "nginx-filesystem-1.24.0-4.oe2403sp1.noarch.rpm",
        "nginx-help-1.24.0-4.oe2403sp1.noarch.rpm",
        "nginx-all-modules-1.24.0-4.oe2403sp1.noarch.rpm",
        "nginx-filesystem-1.24.0-4.oe2403sp1.noarch.rpm",
        "nginx-help-1.24.0-4.oe2403sp1.noarch.rpm"
    ],
    "x86_64": [
        "nginx-1.24.0-3.oe2403.x86_64.rpm",
        "nginx-debuginfo-1.24.0-3.oe2403.x86_64.rpm",
        "nginx-debugsource-1.24.0-3.oe2403.x86_64.rpm",
        "nginx-mod-devel-1.24.0-3.oe2403.x86_64.rpm",
        "nginx-mod-http-image-filter-1.24.0-3.oe2403.x86_64.rpm",
        "nginx-mod-http-perl-1.24.0-3.oe2403.x86_64.rpm",
        "nginx-mod-http-xslt-filter-1.24.0-3.oe2403.x86_64.rpm",
        "nginx-mod-mail-1.24.0-3.oe2403.x86_64.rpm",
        "nginx-mod-stream-1.24.0-3.oe2403.x86_64.rpm",
        "compat-nginx-1.24.0-4.oe2403sp1.x86_64.rpm",
        "compat-nginx-debuginfo-1.24.0-4.oe2403sp1.x86_64.rpm",
        "compat-nginx-debugsource-1.24.0-4.oe2403sp1.x86_64.rpm",
        "compat-nginx-mod-http-image-filter-1.24.0-4.oe2403sp1.x86_64.rpm",
        "compat-nginx-mod-http-perl-1.24.0-4.oe2403sp1.x86_64.rpm",
        "compat-nginx-mod-http-xslt-filter-1.24.0-4.oe2403sp1.x86_64.rpm",
        "compat-nginx-mod-mail-1.24.0-4.oe2403sp1.x86_64.rpm",
        "compat-nginx-mod-stream-1.24.0-4.oe2403sp1.x86_64.rpm",
        "nginx-1.24.0-4.oe2403sp1.x86_64.rpm",
        "nginx-debuginfo-1.24.0-4.oe2403sp1.x86_64.rpm",
        "nginx-debugsource-1.24.0-4.oe2403sp1.x86_64.rpm",
        "nginx-mod-devel-1.24.0-4.oe2403sp1.x86_64.rpm",
        "nginx-mod-http-image-filter-1.24.0-4.oe2403sp1.x86_64.rpm",
        "nginx-mod-http-perl-1.24.0-4.oe2403sp1.x86_64.rpm",
        "nginx-mod-http-xslt-filter-1.24.0-4.oe2403sp1.x86_64.rpm",
        "nginx-mod-mail-1.24.0-4.oe2403sp1.x86_64.rpm",
        "nginx-mod-stream-1.24.0-4.oe2403sp1.x86_64.rpm"
    ],
    "aarch64": [
        "nginx-1.24.0-3.oe2403.aarch64.rpm",
        "nginx-debuginfo-1.24.0-3.oe2403.aarch64.rpm",
        "nginx-debugsource-1.24.0-3.oe2403.aarch64.rpm",
        "nginx-mod-devel-1.24.0-3.oe2403.aarch64.rpm",
        "nginx-mod-http-image-filter-1.24.0-3.oe2403.aarch64.rpm",
        "nginx-mod-http-perl-1.24.0-3.oe2403.aarch64.rpm",
        "nginx-mod-http-xslt-filter-1.24.0-3.oe2403.aarch64.rpm",
        "nginx-mod-mail-1.24.0-3.oe2403.aarch64.rpm",
        "nginx-mod-stream-1.24.0-3.oe2403.aarch64.rpm",
        "compat-nginx-1.24.0-4.oe2403sp1.aarch64.rpm",
        "compat-nginx-debuginfo-1.24.0-4.oe2403sp1.aarch64.rpm",
        "compat-nginx-debugsource-1.24.0-4.oe2403sp1.aarch64.rpm",
        "compat-nginx-mod-http-image-filter-1.24.0-4.oe2403sp1.aarch64.rpm",
        "compat-nginx-mod-http-perl-1.24.0-4.oe2403sp1.aarch64.rpm",
        "compat-nginx-mod-http-xslt-filter-1.24.0-4.oe2403sp1.aarch64.rpm",
        "compat-nginx-mod-mail-1.24.0-4.oe2403sp1.aarch64.rpm",
        "compat-nginx-mod-stream-1.24.0-4.oe2403sp1.aarch64.rpm",
        "nginx-1.24.0-4.oe2403sp1.aarch64.rpm",
        "nginx-debuginfo-1.24.0-4.oe2403sp1.aarch64.rpm",
        "nginx-debugsource-1.24.0-4.oe2403sp1.aarch64.rpm",
        "nginx-mod-devel-1.24.0-4.oe2403sp1.aarch64.rpm",
        "nginx-mod-http-image-filter-1.24.0-4.oe2403sp1.aarch64.rpm",
        "nginx-mod-http-perl-1.24.0-4.oe2403sp1.aarch64.rpm",
        "nginx-mod-http-xslt-filter-1.24.0-4.oe2403sp1.aarch64.rpm",
        "nginx-mod-mail-1.24.0-4.oe2403sp1.aarch64.rpm",
        "nginx-mod-stream-1.24.0-4.oe2403sp1.aarch64.rpm"
    ]
}

openEuler:24.03-LTS-SP1 / nginx

Package

Name
nginx
Purl
pkg:rpm/openEuler/nginx&distro=openEuler-24.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.24.0-4.oe2403sp1

Ecosystem specific

{
    "src": [
        "compat-nginx-1.24.0-4.oe2403sp1.src.rpm",
        "nginx-1.24.0-4.oe2403sp1.src.rpm"
    ],
    "noarch": [
        "compat-nginx-all-modules-1.24.0-4.oe2403sp1.noarch.rpm",
        "compat-nginx-filesystem-1.24.0-4.oe2403sp1.noarch.rpm",
        "compat-nginx-help-1.24.0-4.oe2403sp1.noarch.rpm",
        "nginx-all-modules-1.24.0-4.oe2403sp1.noarch.rpm",
        "nginx-filesystem-1.24.0-4.oe2403sp1.noarch.rpm",
        "nginx-help-1.24.0-4.oe2403sp1.noarch.rpm",
        "nginx-all-modules-1.24.0-4.oe2403sp1.noarch.rpm",
        "nginx-filesystem-1.24.0-4.oe2403sp1.noarch.rpm",
        "nginx-help-1.24.0-4.oe2403sp1.noarch.rpm"
    ],
    "x86_64": [
        "compat-nginx-1.24.0-4.oe2403sp1.x86_64.rpm",
        "compat-nginx-debuginfo-1.24.0-4.oe2403sp1.x86_64.rpm",
        "compat-nginx-debugsource-1.24.0-4.oe2403sp1.x86_64.rpm",
        "compat-nginx-mod-http-image-filter-1.24.0-4.oe2403sp1.x86_64.rpm",
        "compat-nginx-mod-http-perl-1.24.0-4.oe2403sp1.x86_64.rpm",
        "compat-nginx-mod-http-xslt-filter-1.24.0-4.oe2403sp1.x86_64.rpm",
        "compat-nginx-mod-mail-1.24.0-4.oe2403sp1.x86_64.rpm",
        "compat-nginx-mod-stream-1.24.0-4.oe2403sp1.x86_64.rpm",
        "nginx-1.24.0-4.oe2403sp1.x86_64.rpm",
        "nginx-debuginfo-1.24.0-4.oe2403sp1.x86_64.rpm",
        "nginx-debugsource-1.24.0-4.oe2403sp1.x86_64.rpm",
        "nginx-mod-devel-1.24.0-4.oe2403sp1.x86_64.rpm",
        "nginx-mod-http-image-filter-1.24.0-4.oe2403sp1.x86_64.rpm",
        "nginx-mod-http-perl-1.24.0-4.oe2403sp1.x86_64.rpm",
        "nginx-mod-http-xslt-filter-1.24.0-4.oe2403sp1.x86_64.rpm",
        "nginx-mod-mail-1.24.0-4.oe2403sp1.x86_64.rpm",
        "nginx-mod-stream-1.24.0-4.oe2403sp1.x86_64.rpm"
    ],
    "aarch64": [
        "compat-nginx-1.24.0-4.oe2403sp1.aarch64.rpm",
        "compat-nginx-debuginfo-1.24.0-4.oe2403sp1.aarch64.rpm",
        "compat-nginx-debugsource-1.24.0-4.oe2403sp1.aarch64.rpm",
        "compat-nginx-mod-http-image-filter-1.24.0-4.oe2403sp1.aarch64.rpm",
        "compat-nginx-mod-http-perl-1.24.0-4.oe2403sp1.aarch64.rpm",
        "compat-nginx-mod-http-xslt-filter-1.24.0-4.oe2403sp1.aarch64.rpm",
        "compat-nginx-mod-mail-1.24.0-4.oe2403sp1.aarch64.rpm",
        "compat-nginx-mod-stream-1.24.0-4.oe2403sp1.aarch64.rpm",
        "nginx-1.24.0-4.oe2403sp1.aarch64.rpm",
        "nginx-debuginfo-1.24.0-4.oe2403sp1.aarch64.rpm",
        "nginx-debugsource-1.24.0-4.oe2403sp1.aarch64.rpm",
        "nginx-mod-devel-1.24.0-4.oe2403sp1.aarch64.rpm",
        "nginx-mod-http-image-filter-1.24.0-4.oe2403sp1.aarch64.rpm",
        "nginx-mod-http-perl-1.24.0-4.oe2403sp1.aarch64.rpm",
        "nginx-mod-http-xslt-filter-1.24.0-4.oe2403sp1.aarch64.rpm",
        "nginx-mod-mail-1.24.0-4.oe2403sp1.aarch64.rpm",
        "nginx-mod-stream-1.24.0-4.oe2403sp1.aarch64.rpm"
    ]
}

openEuler:20.03-LTS-SP4 / nginx

Package

Name
nginx
Purl
pkg:rpm/openEuler/nginx&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.21.5-6.oe2003sp4

Ecosystem specific

{
    "src": [
        "nginx-1.21.5-6.oe2003sp4.src.rpm"
    ],
    "noarch": [
        "nginx-all-modules-1.21.5-6.oe2003sp4.noarch.rpm",
        "nginx-filesystem-1.21.5-6.oe2003sp4.noarch.rpm"
    ],
    "x86_64": [
        "nginx-1.21.5-6.oe2003sp4.x86_64.rpm",
        "nginx-debuginfo-1.21.5-6.oe2003sp4.x86_64.rpm",
        "nginx-debugsource-1.21.5-6.oe2003sp4.x86_64.rpm",
        "nginx-mod-devel-1.21.5-6.oe2003sp4.x86_64.rpm",
        "nginx-mod-http-image-filter-1.21.5-6.oe2003sp4.x86_64.rpm",
        "nginx-mod-http-perl-1.21.5-6.oe2003sp4.x86_64.rpm",
        "nginx-mod-http-xslt-filter-1.21.5-6.oe2003sp4.x86_64.rpm",
        "nginx-mod-mail-1.21.5-6.oe2003sp4.x86_64.rpm",
        "nginx-mod-stream-1.21.5-6.oe2003sp4.x86_64.rpm"
    ],
    "aarch64": [
        "nginx-1.21.5-6.oe2003sp4.aarch64.rpm",
        "nginx-debuginfo-1.21.5-6.oe2003sp4.aarch64.rpm",
        "nginx-debugsource-1.21.5-6.oe2003sp4.aarch64.rpm",
        "nginx-mod-devel-1.21.5-6.oe2003sp4.aarch64.rpm",
        "nginx-mod-http-image-filter-1.21.5-6.oe2003sp4.aarch64.rpm",
        "nginx-mod-http-perl-1.21.5-6.oe2003sp4.aarch64.rpm",
        "nginx-mod-http-xslt-filter-1.21.5-6.oe2003sp4.aarch64.rpm",
        "nginx-mod-mail-1.21.5-6.oe2003sp4.aarch64.rpm",
        "nginx-mod-stream-1.21.5-6.oe2003sp4.aarch64.rpm"
    ]
}

openEuler:22.03-LTS-SP3 / nginx

Package

Name
nginx
Purl
pkg:rpm/openEuler/nginx&distro=openEuler-22.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.21.5-8.oe2203sp3

Ecosystem specific

{
    "src": [
        "nginx-1.21.5-8.oe2203sp3.src.rpm"
    ],
    "noarch": [
        "nginx-all-modules-1.21.5-8.oe2203sp3.noarch.rpm",
        "nginx-filesystem-1.21.5-8.oe2203sp3.noarch.rpm",
        "nginx-help-1.21.5-8.oe2203sp3.noarch.rpm"
    ],
    "x86_64": [
        "nginx-1.21.5-8.oe2203sp3.x86_64.rpm",
        "nginx-debuginfo-1.21.5-8.oe2203sp3.x86_64.rpm",
        "nginx-debugsource-1.21.5-8.oe2203sp3.x86_64.rpm",
        "nginx-mod-devel-1.21.5-8.oe2203sp3.x86_64.rpm",
        "nginx-mod-http-image-filter-1.21.5-8.oe2203sp3.x86_64.rpm",
        "nginx-mod-http-perl-1.21.5-8.oe2203sp3.x86_64.rpm",
        "nginx-mod-http-xslt-filter-1.21.5-8.oe2203sp3.x86_64.rpm",
        "nginx-mod-mail-1.21.5-8.oe2203sp3.x86_64.rpm",
        "nginx-mod-stream-1.21.5-8.oe2203sp3.x86_64.rpm"
    ],
    "aarch64": [
        "nginx-1.21.5-8.oe2203sp3.aarch64.rpm",
        "nginx-debuginfo-1.21.5-8.oe2203sp3.aarch64.rpm",
        "nginx-debugsource-1.21.5-8.oe2203sp3.aarch64.rpm",
        "nginx-mod-devel-1.21.5-8.oe2203sp3.aarch64.rpm",
        "nginx-mod-http-image-filter-1.21.5-8.oe2203sp3.aarch64.rpm",
        "nginx-mod-http-perl-1.21.5-8.oe2203sp3.aarch64.rpm",
        "nginx-mod-http-xslt-filter-1.21.5-8.oe2203sp3.aarch64.rpm",
        "nginx-mod-mail-1.21.5-8.oe2203sp3.aarch64.rpm",
        "nginx-mod-stream-1.21.5-8.oe2203sp3.aarch64.rpm"
    ]
}

openEuler:22.03-LTS-SP4 / nginx

Package

Name
nginx
Purl
pkg:rpm/openEuler/nginx&distro=openEuler-22.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.21.5-8.oe2203sp4

Ecosystem specific

{
    "src": [
        "nginx-1.21.5-8.oe2203sp4.src.rpm"
    ],
    "noarch": [
        "nginx-all-modules-1.21.5-8.oe2203sp4.noarch.rpm",
        "nginx-filesystem-1.21.5-8.oe2203sp4.noarch.rpm",
        "nginx-help-1.21.5-8.oe2203sp4.noarch.rpm"
    ],
    "x86_64": [
        "nginx-1.21.5-8.oe2203sp4.x86_64.rpm",
        "nginx-debuginfo-1.21.5-8.oe2203sp4.x86_64.rpm",
        "nginx-debugsource-1.21.5-8.oe2203sp4.x86_64.rpm",
        "nginx-mod-devel-1.21.5-8.oe2203sp4.x86_64.rpm",
        "nginx-mod-http-image-filter-1.21.5-8.oe2203sp4.x86_64.rpm",
        "nginx-mod-http-perl-1.21.5-8.oe2203sp4.x86_64.rpm",
        "nginx-mod-http-xslt-filter-1.21.5-8.oe2203sp4.x86_64.rpm",
        "nginx-mod-mail-1.21.5-8.oe2203sp4.x86_64.rpm",
        "nginx-mod-stream-1.21.5-8.oe2203sp4.x86_64.rpm"
    ],
    "aarch64": [
        "nginx-1.21.5-8.oe2203sp4.aarch64.rpm",
        "nginx-debuginfo-1.21.5-8.oe2203sp4.aarch64.rpm",
        "nginx-debugsource-1.21.5-8.oe2203sp4.aarch64.rpm",
        "nginx-mod-devel-1.21.5-8.oe2203sp4.aarch64.rpm",
        "nginx-mod-http-image-filter-1.21.5-8.oe2203sp4.aarch64.rpm",
        "nginx-mod-http-perl-1.21.5-8.oe2203sp4.aarch64.rpm",
        "nginx-mod-http-xslt-filter-1.21.5-8.oe2203sp4.aarch64.rpm",
        "nginx-mod-mail-1.21.5-8.oe2203sp4.aarch64.rpm",
        "nginx-mod-stream-1.21.5-8.oe2203sp4.aarch64.rpm"
    ]
}