CVE-2022-41741
published 2022-10-19CVE-2022-41741: NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.76%
51.0th percentile
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its termination or potential other impact using a specially crafted audio or video file. The issue affects only NGINX products that are built with the ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | nginx | < nginx 1.22.1-1 (bookworm) | nginx 1.22.1-1 (bookworm) |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | >= 0 < 1.18.0-6.1+deb11u3 | 1.18.0-6.1+deb11u3 |
| f5 | nginx | >= 0 < 1.22.1-1 | 1.22.1-1 |
| f5 | nginx | >= 0 < 1.22.1-1 | 1.22.1-1 |
| f5 | nginx | >= 0 < 1.22.1-1 | 1.22.1-1 |
| f5 | nginx | >= 0 < 1.14.0-0ubuntu1.11 | 1.14.0-0ubuntu1.11 |
| f5 | nginx | >= 0 < 1.18.0-0ubuntu1.4 | 1.18.0-0ubuntu1.4 |
| f5 | nginx | >= 0 < 1.18.0-6ubuntu14.3 | 1.18.0-6ubuntu14.3 |
| f5 | nginx | >= 0 < 1.4.6-1ubuntu3.9+esm4 | 1.4.6-1ubuntu3.9+esm4 |
| f5 | nginx | >= 0 < 1.10.3-0ubuntu0.16.04.5+esm5 | 1.10.3-0ubuntu0.16.04.5+esm5 |
| f5 | nginx | 1.1.3 – 1.22.0 | — |
| f5 | nginx | >= Mainline < 1.23.2 | 1.23.2 |
| f5 | nginx | >= Stable < 1.22.1 | 1.22.1 |
| f5 | nginx | r22 – r27 | — |
| f5 | nginx_ingress_controller | — | — |
| f5 | nginx_ingress_controller | 1.9.0 – 1.12.4 | — |
| f5 | nginx_ingress_controller | 2.0.0 – 2.4.0 | — |
| f5 | nginx_open_source_subscription | >= R1 < R1 P1 | R1 P1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_msrc7.8HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2025-02-12·CVSS 7.1
CVE-2015-5312 [HIGH] PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
T he Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2015-5312, CVE-2016-4607, CVE-2016-4608, CVE-2016-4609, CVE-2016-4738, CVE-2018-1111, CVE-2018-14634, CVE-2018-18653, CVE-2019-0145, CVE-2019-8331, CVE-2020-0599, CVE-2020-14343, CVE-2020-14779, CVE-2020-27844, CVE-2020-29569, CVE-2021-21315, CVE-2021-27853, CVE-2021-27854, CVE-2021-27861, CVE-2021-27862, CVE-2021-3618, CVE-2021-3711, CVE-2022-2097, CVE-2022-22816, CVE-2022-40303, CVE-2022-41723, CVE-2022-41741, CVE-2022-41742, CVE-2023-3247, CVE-2023-38408, CVE-2023-44466, CVE-2023-50781, CVE-2023-50782, CVE-2024-12084, CV
Ubuntu
nginx vulnerabilities
vendor_ubuntu·2022-11-15·CVSS 7.0
CVE-2022-41741 [HIGH] nginx vulnerabilities
Title: nginx vulnerabilities
Summary: Several security issues were fixed in nginx.
It was discovered that nginx incorrectly handled certain memory operations in
the ngx_http_mp4_module module. A local attacker could possibly use this issue
with a specially crafted mp4 file to cause nginx to crash, stop responding, or
access arbitrary memory. (CVE-2022-41741, CVE-2022-41742)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
nginx: Memory corruption in the ngx_http_mp4_module
vendor_redhat·2022-10-19·CVSS 7.0
CVE-2022-41741 [HIGH] CWE-787 nginx: Memory corruption in the ngx_http_mp4_module
nginx: Memory corruption in the ngx_http_mp4_module
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its termination or potential other impact using a specially crafted audio or video file. The issue affects only NGINX products that are built with the ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.
A vulnerability was found in NGINX's module, ngx_http_mp4_mod
F5
CVE-2022-41741: NGINX Open Source before versions 1
vendor_f5·2022-10-19·CVSS 7.0
CVE-2022-41741 [HIGH] CWE-787 CVE-2022-41741: NGINX Open Source before versions 1
CVE-2022-41741: NGINX Open Source before versions 1
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its termination or potential other impact using a specially crafted audio or video file. The issue affects only NGINX products that are built with the ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.
Affected Products: NGINX, NGINX Ingress Controller, NGINX Plu
Microsoft
NGINX ngx_http_mp4_module vulnerability CVE-2022-41741
vendor_msrc·2022-10-11·CVSS 7.8
CVE-2022-41741 [HIGH] CWE-787 NGINX ngx_http_mp4_module vulnerability CVE-2022-41741
NGINX ngx_http_mp4_module vulnerability CVE-2022-41741
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
f5: f5
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.micros
Debian
CVE-2022-41741: nginx - NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscript...
vendor_debian·2022·CVSS 7.0
CVE-2022-41741 [HIGH] CVE-2022-41741: nginx - NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscript...
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its termination or potential other impact using a specially crafted audio or video file. The issue affects only NGINX products that are built with the ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.
Scope: local
bookworm: resolved (fixed in 1.22.1-1)
bullseye: resolved (fixed in 1.18.0-6.1+deb11u3)
forky: resolve
OSV
nginx vulnerabilities
osv·2022-11-15·CVSS 7.8
CVE-2022-41741 [HIGH] nginx vulnerabilities
nginx vulnerabilities
It was discovered that nginx incorrectly handled certain memory operations in
the ngx_http_mp4_module module. A local attacker could possibly use this issue
with a specially crafted mp4 file to cause nginx to crash, stop responding, or
access arbitrary memory. (CVE-2022-41741, CVE-2022-41742)
GHSA
GHSA-3v5h-538g-pr7g: NGINX Open Source before versions 1
ghsa_unreviewed·2022-10-20
CVE-2022-41741 [HIGH] CWE-787 GHSA-3v5h-538g-pr7g: NGINX Open Source before versions 1
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its termination or potential other impact using a specially crafted audio or video file. The issue affects only NGINX products that are built with the ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.
OSV
CVE-2022-41741: NGINX Open Source before versions 1
osv·2022-10-19·CVSS 7.8
CVE-2022-41741 [HIGH] CVE-2022-41741: NGINX Open Source before versions 1
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its termination or potential other impact using a specially crafted audio or video file. The issue affects only NGINX products that are built with the ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.
No detection rules found.
No public exploits indexed.
https://lists.debian.org/debian-lts-announce/2022/11/msg00031.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BPRVYA4FS34VWB4FEFYNAD7Z2LFCJVEI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FD6M3PVVKO35WLAA7GLDBS6TEQ26SM64/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WBORRVG7VVXYOAIAD64ZHES2U2VIUKFQ/https://security.netapp.com/advisory/ntap-20230120-0005/https://support.f5.com/csp/article/K81926432https://www.debian.org/security/2022/dsa-5281https://lists.debian.org/debian-lts-announce/2022/11/msg00031.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BPRVYA4FS34VWB4FEFYNAD7Z2LFCJVEI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FD6M3PVVKO35WLAA7GLDBS6TEQ26SM64/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WBORRVG7VVXYOAIAD64ZHES2U2VIUKFQ/https://security.netapp.com/advisory/ntap-20230120-0005/https://support.f5.com/csp/article/K81926432https://www.debian.org/security/2022/dsa-5281
2022-10-19
Published