CVE-2023-44487
nginxVulnerabilityPatched
No public exploitation has been reported so far. A fixed version is available (see the table below).
Recommended action: Update to the fixed version listed for your distribution using the native package manager.
Affected & fixed versions by distribution
Versions are the native distribution strings (backport-aware): RHEL/Debian/SUSE backport fixes, so compare with the distro version comparator (dpkg / rpm / vercmp), not the upstream version.
| Distribution | Package | Affected | Fixed version | Status |
|---|---|---|---|---|
| Debian:11 | nginx | - | - | affected (no fix yet) |
| Debian:12 | nginx | - | - | affected (no fix yet) |
| Debian:13 | nginx | - | 1.24.0-2 | fixed |
| Debian:14 | nginx | - | 1.24.0-2 | fixed |
| Debian:11 | varnish | - | - | affected (no fix yet) |
| Debian:12 | varnish | - | - | affected (no fix yet) |
| Debian:13 | varnish | - | 7.5.0-1 | fixed |
| SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS | nginx | - | 1.21.5-150400.3.6.1 | fixed |
| SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS | nginx | - | 1.21.5-150400.3.6.1 | fixed |
| SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS | nginx | - | 1.21.5-150400.3.6.1 | fixed |
| SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS | nginx | - | 1.21.5-150400.3.6.1 | fixed |
| SUSE:Linux Enterprise Server 15 SP4-LTSS | nginx | - | 1.21.5-150400.3.6.1 | fixed |
| SUSE:Linux Enterprise Server 15 SP5-LTSS | nginx | - | 1.21.5-150400.3.6.1 | fixed |
| SUSE:Linux Enterprise Server for SAP Applications 15 SP4 | nginx | - | 1.21.5-150400.3.6.1 | fixed |
| SUSE:Linux Enterprise Server for SAP Applications 15 SP5 | nginx | - | 1.21.5-150400.3.6.1 | fixed |
| SUSE:Manager Proxy 4.3 | nginx | - | 1.21.5-150400.3.6.1 | fixed |
| SUSE:Manager Server 4.3 | nginx | - | 1.21.5-150400.3.6.1 | fixed |
| SUSE:Linux Enterprise Module for Server Applications 15 SP6 | nginx | - | 1.21.5-150600.10.3.1 | fixed |
| openSUSE:Leap 15.6 | nginx | - | 1.21.5-150600.10.3.1 | fixed |
| openSUSE:Tumbleweed | apache2 | - | 2.4.58-1.1 | fixed |
| openSUSE:Tumbleweed | varnish | - | 7.4.2-1.1 | fixed |
| Red Hat:openshift:4.14::el9 | kernel | - | 0:5.14.0-284.36.1.el9_2 | fixed |
| Red Hat:enterprise_linux:9::appstream | nginx | - | 1:1.22.1-5.module+el9.3.0.z+20438+032561a0 | fixed |
| Red Hat:enterprise_linux:9::appstream | nginx | - | 1:1.20.1-14.el9_2.1 | fixed |
| Red Hat:enterprise_linux:8::appstream | nginx | - | 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1 | fixed |
| Red Hat:enterprise_linux:8::appstream | nginx | - | 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1 | fixed |
| Red Hat:rhel_eus:9.0::appstream | nginx | - | 1:1.20.1-10.el9_0.1 | fixed |
| Red Hat:rhel_eus:8.6::appstream | nginx | - | 1:1.20.1-1.module+el8.6.0+20350+58c16214.1 | fixed |
| Red Hat:enterprise_linux:9::appstream | nginx | - | 1:1.22.1-3.module+el9.2.0.z+20353+5a828d50.1 | fixed |
| Red Hat:enterprise_linux:9::appstream | varnish | - | 0:6.6.2-3.el9_2.1 | fixed |
| Red Hat:rhel_eus:9.0::appstream | varnish | - | 0:6.6.2-2.el9_0.2 | fixed |
| Red Hat:enterprise_linux:8::appstream | varnish | - | 0:6.0.8-3.module+el8.8.0+20455+bdc2c048.1 | fixed |
| Red Hat:rhel_eus:8.6::appstream | varnish | - | 0:6.0.8-2.module+el8.6.0+20465+cbb0694f.2 | fixed |
| Red Hat:rhel_aus:8.4::appstream | varnish | - | 0:6.0.6-2.module+el8.4.0+20467+7fe641ed.4 | fixed |
| Red Hat:rhel_e4s:8.4::appstream | varnish | - | 0:6.0.6-2.module+el8.4.0+20467+7fe641ed.4 | fixed |
| Red Hat:rhel_tus:8.4::appstream | varnish | - | 0:6.0.6-2.module+el8.4.0+20467+7fe641ed.4 | fixed |
| Red Hat:rhel_aus:8.2::appstream | varnish | - | 0:6.0.2-2.module+el8.2.0+20470+5fdd0c40.3 | fixed |
| Red Hat:rhel_e4s:8.2::appstream | varnish | - | 0:6.0.2-2.module+el8.2.0+20470+5fdd0c40.3 | fixed |
| Red Hat:rhel_tus:8.2::appstream | varnish | - | 0:6.0.2-2.module+el8.2.0+20470+5fdd0c40.3 | fixed |
| Red Hat:rhel_e4s:8.1::appstream | varnish | - | 0:6.0.2-2.module+el8.1.0+20476+646a44ec.3 | fixed |