When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Nginx_open_source | F5 | 0.5.15 (including) | 0.9.7 (including) |
| Nginx_open_source | F5 | 1.0.0 (including) | 1.28.3 (excluding) |
| Nginx_open_source | F5 | 1.29.0 (including) | 1.29.7 (excluding) |
| Nginx_plus | F5 | r33 (including) | r35 (excluding) |
| Nginx_plus | F5 | r32 (including) | r32 (including) |
| Nginx_plus | F5 | r32-p1 (including) | r32-p1 (including) |
| Nginx_plus | F5 | r32-p2 (including) | r32-p2 (including) |
| Nginx_plus | F5 | r32-p3 (including) | r32-p3 (including) |
| Nginx_plus | F5 | r32-p4 (including) | r32-p4 (including) |
| Nginx_plus | F5 | r35 (including) | r35 (including) |
| Nginx_plus | F5 | r35-p1 (including) | r35-p1 (including) |
| Nginx_plus | F5 | r36 (including) | r36 (including) |
| Nginx_plus | F5 | r36-p1 (including) | r36-p1 (including) |
| Nginx_plus | F5 | r36-p2 (including) | r36-p2 (including) |
| Red Hat Enterprise Linux 10 | RedHat | nginx-2:1.26.3-2.el10_1.1 | * |
| Red Hat Enterprise Linux 10.0 Extended Update Support | RedHat | nginx-2:1.26.3-1.el10_0.8 | * |
| Red Hat Enterprise Linux 8 | RedHat | nginx:1.24-8100020260401080144.489197e6 | * |
| Red Hat Enterprise Linux 9 | RedHat | nginx:1.24-9070020260331134728.9 | * |
| Red Hat Enterprise Linux 9 | RedHat | nginx-2:1.20.1-24.el9_7.2 | * |
| Red Hat Enterprise Linux 9 | RedHat | nginx:1.26-9070020260407080353.9 | * |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | RedHat | nginx-1:1.20.1-10.el9_0.3 | * |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | RedHat | nginx-1:1.20.1-14.el9_2.5 | * |
| Red Hat Enterprise Linux 9.4 Extended Update Support | RedHat | nginx-1:1.20.1-16.el9_4.5 | * |
| Red Hat Enterprise Linux 9.4 Extended Update Support | RedHat | nginx:1.24-9040020260504195322.9 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | nginx-2:1.20.1-22.el9_6.5 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | nginx:1.24-9060020260504194843.9 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | nginx:1.26-9060020260504154614.9 | * |
| Red Hat Hardened Images | RedHat | nginx-main-1.30.0-1.hum1 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/cds-rhel9:1776868774 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/rhua-rhel9:1776868842 | * |
| Nginx | Ubuntu | esm-infra-legacy/trusty | * |
| Nginx | Ubuntu | esm-infra-legacy/xenial | * |
| Nginx | Ubuntu | esm-infra/bionic | * |
| Nginx | Ubuntu | esm-infra/focal | * |
| Nginx | Ubuntu | esm-infra/xenial | * |
| Nginx | Ubuntu | jammy | * |
| Nginx | Ubuntu | noble | * |
| Nginx | Ubuntu | questing | * |
| Nginx | Ubuntu | upstream | * |