
ソースビルドされたnginx 1.25.5コンテナ、CVE-2026-42945修正のバックポート、OpenSSLのバージョンアップ、完全な証明連鎖、およびVEX証明書付き。
nginx:1.25-bookworm 向け公式の nginx:1.25-bookworm イメージに存在する2つのCVEを修正し、上流のランタイム動作を維持する、ソースビルドされたnginx 1.25.5コンテナイメージです。
| CVE | コンポーネント | 深刻度 | 手法 | 検証モデル |
|---|---|---|---|---|
| CVE-2024-6119 | OpenSSL / libssl3 | 高 | 依存関係のバージョンアップ | スキャナー検証可能: dpkgデータベースに表示されるlibssl3 3.0.20 |
| CVE-2026-42945 | nginx ngx_http_rewrite_module | クリティカル | バックポートされたソースパッチ | 発祥検証可能: パッチの派生 + 回帰テスト + ビルド証明 + VEX |
これらは2つの異なる修正モデルを表しています。
このイメージのnginx -V構成引数は、nginx:1.25-bookwormのものと一致します(-ffile-prefix-mapビルドパスを正規化した後、文字単位で比較;test/compat.py::test_nginx_versionで検証済み)。
テストスイート(make test)は、イメージメタデータ、動的モジュール、ファイルシステムレイアウト、エントリポイント動作、dpkgパッケージング、およびライブ上流イメージに対するHTTPリクエスト処理をカバーする89のアサーションを検証します。
上流との既知の相違点(同一であると検証されていないもの):
nginx -Vのbuilt with OpenSSL X.X.X行はビルダーのlibssl-devバージョンを反映しており、上流のコンパイル時のOpenSSLとは異なる可能性があります。debian:bookworm-slimベースです。libssl3バージョンは、上流イメージの固定バージョンではなく、bookwormが現在提供するもの(執筆時点では3.0.20)です。make image
make test
make test-cve
make verify-patch
make scan
ビルド、テスト、スキャンを1つのコマンドで:```bash
make all
build/ Dockerfile.build Builder image (debian:bookworm-slim + compilation deps) build.sh Fetch → verify → patch → compile → package nginx generate-vex.sh Generate OpenVEX document for backported CVE verify-patch.sh Re-derive patch from upstream tarballs (audit tool) patches/ CVE-2026-42945.patch Backported one-line fix from nginx 1.30.1 CVE-2026-42945.provenance.json Machine-readable patch provenance and derivation metadata
test/ compat.py 89-assertion compatibility test suite (runs against live upstream) test_cve_2026_42945.py CVE-specific regression test (exercises vulnerable code path)
artifacts/
patch-attestation.json Build-time patch attestation (tracked)
nginx_*.deb Compiled package (gitignored - rebuilt via make build-source)
nginx Compiled binary (gitignored)
Containerfile Final runtime image definition
Makefile Orchestrates build → test → scan pipeline
vex.json Generated OpenVEX v0.2.0 document
baseline-trivy.txt Point-in-time Trivy scan of nginx:1.25-bookworm
baseline-grype.txt Point-in-time Grype scan of nginx:1.25-bookworm
fixed-trivy.txt Trivy scan of the fixed image
fixed-grype.txt Grype scan of the fixed image (without VEX)
fixed-grype-vex.txt Grype scan of the fixed image (with VEX applied)
---
## ビルドプロセス
### アーキテクチャ```
debian:bookworm-slim (builder)
└─ build.sh
├─ curl nginx-1.25.5.tar.gz (SHA256-verified)
├─ curl njs-0.8.4 from github.com/nginx/njs
├─ patch -p1 < CVE-2026-42945.patch
├─ ./configure (flags identical to upstream nginx -V)
├─ make: release binary, debug binary, 4 dynamic module families (×2 release/debug)
├─ make: NJS modules (×2 release/debug) + njs CLI binary
└─ dpkg-deb → nginx_1.25.5-1~bookworm+echo1_<arch>.deb
debian:bookworm-slim (runtime)
├─ apt-get install runtime deps (libssl3 ≥ 3.0.14 enforced)
├─ dpkg -i nginx_*.deb
└─ COPY --from=upstream /docker-entrypoint.sh + /docker-entrypoint.d/
Containerfileは、上流から/etc/nginxをコピーしません。すべての設定ファイルは.deb内に同梱され、dpkgのconffileメカニズムによって追跡されます。これは、default.confがユーザーによって変更されたかどうかを検出するためにdpkg-queryを使用する10-listen-on-ipv6-by-default.shエントリポイントスクリプトに必要です。
./configure && makeを実行します。上流のバイナリは使用せず、apt install nginxも行いません。build.shは固定されたソースアーカイブのみを取得します。ビルドは_ほぼ_再現可能ですが、完全に密閉(hermetic)ではありません。
Dockerfile.buildに列挙されていますが、バージョンは固定されていません。再現性を向上させるには、ベースイメージのダイジェストを固定してください:```bash docker pull debian:bookworm-slim docker inspect debian:bookworm-slim --format='{{index .RepoDigests 0}}'
---
## CVE 修復の詳細
### CVE-2024-6119 - OpenSSL バージョンアップ
| フィールド | 値 |
| -------------------- | ---------------------------------------------------- |
| **コンポーネント** | OpenSSL / libssl3 |
| **深刻度** | 高 (CVSS 7.5) |
| **タイプ** | X.509 名前チェックによるサービス拒否 |
| **ベースライン版** | 3.0.11-1~deb12u2 |
| **修正版** | 3.0.14-1~deb12u2 (以降) |
| **自社版** | 3.0.20-1~deb12u1 |
| **NVD** | https://nvd.nist.gov/vuln/detail/CVE-2024-6119 |
| **勧告** | https://openssl-library.org/news/secadv/20240903.txt |
**修正の仕組み:**
`.deb` パッケージは `Depends: libssl3 (>= 3.0.14)` を宣言しており、これにより
`apt-get install` は修正を含む OpenSSL バージョンを強制的に取得します。現在の
Debian bookworm リポジトリでは 3.0.20 が提供されており、CVE-2024-6119 および
ベースライン由来の数十もの他の OpenSSL CVE (CVE-2024-2511、CVE-2024-5535、
CVE-2024-4741、CVE-2023-5678、CVE-2023-6129、CVE-2023-6237、CVE-2024-9143、
CVE-2025-15467、CVE-2025-69420) を修正しています。
**スキャナーの動作:** Grype および Trivy は dpkg データベース内の `libssl3 3.0.20` を認識し、
3.0.20 ≥ 3.0.14 であると判断するため、CVE-2024-6119 は報告されなくなります。
VEX は不要です。バージョンアップ自体が自明です。
**検証:**```bash
grep "CVE-2024-6119" baseline-grype.txt # present
grep "CVE-2024-6119" fixed-grype.txt # absent
| フィールド | 値 |
|---|---|
| コンポーネント | nginx ngx_http_rewrite_module |
| 重大度 | Medium(nginx.org の分類) |
| ベースライン バージョン | nginx 1.25.5 |
| 修正バージョン | nginx 1.30.1(リリース日 2026-05-13) |
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-42945 |
| セキュリティアドバイザリ | https://my.f5.com/manage/s/article/K000161019 |
| アップストリームの変更 | nginx 1.30.1 CHANGES: "rewrite モジュールにおけるヒープメモリバッファオーバーフロー" |
脆弱性:
ngx_http_script_regex_end_code() が src/http/ngx_http_script.c 内で、rewrite の正規表現結果を処理する際に e->is_args のリセットに失敗しました。is_args が先行するスクリプトエンジン操作によって設定されていた場合、リダイレクト/rewrite パスでの後続のバッファ長の計算が誤りとなり、細工されたリクエスト URI を介して攻撃者が制御可能なサイズのヒープバッファオーバーフローを引き起こします。
修正(1行):```c // Added before the existing e->quote = 0; at line 1205 e->is_args = 0;
**パッチの出典:**