Index | Thread | Search

From:
Mark Patruck <mark@wrapped.cx>
Subject:
Re: www/nginx 1.30.2 - fixing CVE-2026-9256 (buffer overflow)
To:
Jeremie Courreges-Anglas <jca@wxcvbn.org>
Cc:
Robert Nagy <robert@openbsd.org>, ports@openbsd.org
Date:
Mon, 25 May 2026 13:52:01 +0200

Download raw body.

Thread
On 25.05.2026 12:14, Jeremie Courreges-Anglas wrote:
>On Sat, May 23, 2026 at 11:18:38AM +0200, Mark Patruck wrote:
>> Update to www/nginx 1.30.2 released yesterday fixing
>>
>> - CVE-2026-9256 (buffer overflow in ngx_http_rewrite_module)
>
>Thanks Mark.  Your diff doesn't apply, your MUA likely mangled it -
>see format=flowed.  The diff below does apply.  I'll likely commit it
>later today unless robert@ beats me to it (ok jca@).

I've had that mangled diff fun with robert@ a few times already
and still don't know where it comes from. The diff applies fine
against -current here and has been attached to my mail in neomutt
via ':r diff' like always.

Anyway, thanks for comitting.

	-Mark

--
Mark Patruck ( mark at wrapped.cx )
GPG key 0xF2865E51 / 187F F6D3 EE04 1DCE 1C74  F644 0D3C F66F F286 5E51
  
https://www.wrapped.cx