About CVE-2024-7347 in AlmaLinux 9 / nginx:1.24

Hello,

I am wondering about the status of this report, and if it’s currently in a queue.

errata has the fix for:

  • nginx (1.20) - ALSA-2025:7402 (which matches RHSA-2025:7402)
  • nginx:1.22 - ALSA-2025:3261 (which matches RHSA-2025:3261)

However, I cannot see a fix for nginx:1.24 (whereas RHSA-2025:3262 exists)

Thanks a lot,

Hello

For an authoritative answer regarding the release schedule or policy for AlmaLinux Errata (especially for nginx:1.24), I recommend asking directly in the AlmaLinux Security channel:

https://chat.almalinux.org/almalinux/channels/security

The AlmaLinux team and maintainers are active there, and they can provide official information about Errata publication and package availability.

Hello
Thanks for catching that.
The fixed version is available in the repositories: nginx-1.24.0-4.

The errata will be released in a few days

1 Like

This topic was automatically closed 360 days after the last reply. New replies are no longer allowed.