Cov ceg tseem ceeb ntawm nginx 1.25.4 tau raug tso tawm, nyob rau hauv uas txoj kev loj hlob ntawm cov yam ntxwv tshiab txuas ntxiv mus. Cov ceg ntoo ruaj khov uas muaj qhov sib npaug 1.24.x tsuas muaj kev hloov pauv cuam tshuam txog kev tshem tawm cov kab mob hnyav thiab qhov tsis zoo. Nyob rau hauv lub neej yav tom ntej, raws li lub ntsiab ceg 1.25.x, ib ceg ruaj khov 1.26 yuav raug tsim. Txoj haujlwm code yog sau rau hauv C thiab faib raws li BSD daim ntawv tso cai.
Cov version tshiab kho ob qhov tsis zoo hauv qhov kev sim http_v3_module (tsis ua haujlwm los ntawm lub neej ntawd), uas muab kev txhawb nqa rau HTTP/3 protocol, uas siv QUIC protocol ua tus thauj mus rau HTTP/2. Qhov tsis zoo thawj zaug (CVE-2024-24989) yog tshwm sim los ntawm NULL pointer dereference, thiab qhov thib ob (CVE-2024-24990) yog tshwm sim los ntawm use-after-free (CVE-2024-24990). Daim changelog hais tias ob qho kev tsis zoo tsuas yog ua rau muaj kev sib tsoo thaum tswj hwm cov kev sib tham QUIC tshwj xeeb, tab sis nws zoo li qhov tsis zoo thib ob tsis tau raug tshuaj xyuas rau qhov tshwm sim loj dua.
Ntxiv rau kev kho qhov tsis zoo, qhov version tshiab kuj suav nrog kev txhim kho dav dav thiab kev kho rau HTTP/3 kev siv, nrog rau kev kho rau qhov xau socket, qhov yuam kev socket, thiab kev sib tsoo thaum siv AIO. Qhov teeb meem nrog kev kaw cov kev sib txuas ua ntej nrog cov haujlwm AIO tsis tiav thaum lub sijhawm xaus ntawm cov txheej txheem ua haujlwm qub tau daws tau lawm. Kev sib tsoo thaum redirecting 415 qhov yuam kev siv cov lus qhia error_page tau kho lawm, thaum siv SSL-proxying thiab cov lus qhia image_filter.
Tsis tas li ntawd, ob peb hnub dhau los, njs 0.8.4, tus neeg txhais lus JavaScript rau web server nginx. Tus neeg txhais lus njs siv cov qauv ECMAScript thiab tso cai rau koj txuas ntxiv nginx cov peev xwm ua cov lus thov siv cov ntawv sau teeb tsa. Cov ntawv sau tuaj yeem siv hauv cov ntaub ntawv teeb tsa los txhais cov lus thov ua tiav qib siab, tsim cov kev teeb tsa, tsim cov lus teb dynamically, hloov kho cov lus thov / cov lus teb, lossis tsim cov stubs sai sai los daws cov teeb meem hauv cov ntawv thov web. Cov version tshiab tsuas yog muaj cov kab laum kho.
Tau qhov twg los: opennet.ru
