RHSA-2025:7331MediumCVSS 4.3

Red Hat Security Advisory: nginx security update

Published
May 13, 2025
Last Modified
August 6, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2025-23419 — nginx: TLS Session Resumption Vulnerability

🎯 Affected products101

  • Red Hat Enterprise Linux AppStream (v. 9)
  • Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • nginx-2:1.20.1-22.el9.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nginx-2:1.20.1-22.el9.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nginx-2:1.20.1-22.el9.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nginx-2:1.20.1-22.el9.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nginx-2:1.20.1-22.el9.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nginx-all-modules-2:1.20.1-22.el9.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nginx-core-2:1.20.1-22.el9.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nginx-core-2:1.20.1-22.el9.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nginx-core-2:1.20.1-22.el9.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nginx-core-2:1.20.1-22.el9.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nginx-core-debuginfo-2:1.20.1-22.el9.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nginx-core-debuginfo-2:1.20.1-22.el9.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • nginx-core-debuginfo-2:1.20.1-22.el9.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nginx-core-debuginfo-2:1.20.1-22.el9.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • nginx-core-debuginfo-2:1.20.1-22.el9.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nginx-core-debuginfo-2:1.20.1-22.el9.s390x as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • nginx-core-debuginfo-2:1.20.1-22.el9.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nginx-core-debuginfo-2:1.20.1-22.el9.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • nginx-debuginfo-2:1.20.1-22.el9.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nginx-debuginfo-2:1.20.1-22.el9.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • nginx-debuginfo-2:1.20.1-22.el9.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nginx-debuginfo-2:1.20.1-22.el9.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • nginx-debuginfo-2:1.20.1-22.el9.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nginx-debuginfo-2:1.20.1-22.el9.s390x as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • nginx-debuginfo-2:1.20.1-22.el9.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nginx-debuginfo-2:1.20.1-22.el9.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • nginx-debugsource-2:1.20.1-22.el9.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nginx-debugsource-2:1.20.1-22.el9.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • +71 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.

🔗 References (5)