Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
nginx-cve-fix — 从源码构建的nginx 1.25.5容器,包含向后移植的CVE-2026-42945修复、OpenSSL升级、完整的来源链以及VEX attestation。 | Kitploit
工具/GitHubGitHub/barappteam/nginx-cve-fix
漏洞扫描器容器安全漏洞分析配置审计DevSecOps供应链安全
GitHubbarappteam/nginx-cve-fix

nginx-cve-fix

从源码构建的nginx 1.25.5容器,包含向后移植的CVE-2026-42945修复、OpenSSL升级、完整的来源链以及VEX attestation。

查看仓库
224个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

Nginx CVE 修复 - 用于 nginx:1.25-bookworm 的源构建即插即用替换

一个源构建的 nginx 1.25.5 容器镜像,它修复了官方 nginx:1.25-bookworm 镜像中存在的两个 CVE,同时保留了上游运行时行为。

CVE组件严重程度技术验证模型
CVE-2024-6119OpenSSL / libssl3高依赖版本升级扫描器可验证:libssl3 3.0.20 在 dpkg 数据库中可见
CVE-2026-42945nginx ngx_http_rewrite_module严重向后移植源补丁来源可验证:补丁推导 + 回归测试 + 构建证明 + VEX

这两种代表了两种不同的修复模型:

  1. 版本升级(CVE-2024-6119)- 修复后的库版本通过 dpkg 数据库直接对扫描器可见。无需额外证明。
  2. 源补丁向后移植(CVE-2026-42945)- 包版本仍为 1.25.5,因此扫描器无法区分修补后的二进制文件与未修补的版本。通过源来源、构建时验证和回归测试来证明修复。VEX 提供扫描器层的信号。

对等状态

此镜像的 nginx -V 配置参数匹配 nginx:1.25-bookworm(在规范化 -ffile-prefix-map 构建路径后逐字符比较;在 test/compat.py::test_nginx_version 中验证)。测试套件(make test)针对实时上游镜像验证了 89 个断言,涵盖镜像元数据、动态模块、文件系统布局、入口点行为、dpkg 打包和 HTTP 请求处理。

与上游的已知差异(未经验证为相同):

  • nginx -V 中的 built with OpenSSL X.X.X 行反映构建者的 libssl-dev 版本,可能不同于上游编译时的 OpenSSL。
  • 二进制内容并非逐字节相同(不同的编译环境、不同的工具链调用时间戳)。
  • 镜像包集合不同 - 基础镜像为 debian:bookworm-slim,而非官方镜像继承的包树。
  • 运行时的 libssl3 版本是 bookworm 当前提供的版本(撰写时为 3.0.20),而非上游镜像中固定的版本。

快速开始```bash

Build everything (builder → .deb → final image)

make image

Run automated compatibility tests

make test

Run CVE-2026-42945 regression test

make test-cve

Verify patch provenance (re-derives from upstream tarballs)

make verify-patch

Scan and demonstrate VEX

make scan

一个命令用于构建、测试和扫描:```bash
make all

仓库结构```

build/ Dockerfile.build Builder image (debian:bookworm-slim + compilation deps) build.sh Fetch → verify → patch → compile → package nginx generate-vex.sh Generate OpenVEX document for backported CVE verify-patch.sh Re-derive patch from upstream tarballs (audit tool) patches/ CVE-2026-42945.patch Backported one-line fix from nginx 1.30.1 CVE-2026-42945.provenance.json Machine-readable patch provenance and derivation metadata

test/ compat.py 89-assertion compatibility test suite (runs against live upstream) test_cve_2026_42945.py CVE-specific regression test (exercises vulnerable code path)

artifacts/ patch-attestation.json Build-time patch attestation (tracked) nginx_*.deb Compiled package (gitignored - rebuilt via make build-source) nginx Compiled binary (gitignored) Containerfile Final runtime image definition Makefile Orchestrates build → test → scan pipeline vex.json Generated OpenVEX v0.2.0 document baseline-trivy.txt Point-in-time Trivy scan of nginx:1.25-bookworm baseline-grype.txt Point-in-time Grype scan of nginx:1.25-bookworm fixed-trivy.txt Trivy scan of the fixed image fixed-grype.txt Grype scan of the fixed image (without VEX) fixed-grype-vex.txt Grype scan of the fixed image (with VEX applied)

---

## 构建过程

### 架构```
debian:bookworm-slim (builder)
  └─ build.sh
       ├─ curl nginx-1.25.5.tar.gz (SHA256-verified)
       ├─ curl njs-0.8.4 from github.com/nginx/njs
       ├─ patch -p1 < CVE-2026-42945.patch
       ├─ ./configure (flags identical to upstream nginx -V)
       ├─ make: release binary, debug binary, 4 dynamic module families (×2 release/debug)
       ├─ make: NJS modules (×2 release/debug) + njs CLI binary
       └─ dpkg-deb → nginx_1.25.5-1~bookworm+echo1_<arch>.deb

debian:bookworm-slim (runtime)
  ├─ apt-get install runtime deps (libssl3 ≥ 3.0.14 enforced)
  ├─ dpkg -i nginx_*.deb
  └─ COPY --from=upstream /docker-entrypoint.sh + /docker-entrypoint.d/

The Containerfile does NOT copy /etc/nginx from upstream. All configuration files are shipped inside the .deb and tracked by dpkg's conffile mechanism. This is required for the 10-listen-on-ipv6-by-default.sh entrypoint script, which uses dpkg-query to detect whether default.conf has been user-modified.

完整性保证

  • 源压缩包:所有源代码归档(nginx、NJS)在解压前都使用硬编码哈希进行 SHA256 校验。不匹配时构建中止。
  • 从源代码构建:在干净的 Debian 容器内执行 ./configure && make。无上游二进制文件,不使用 apt install nginx。
  • 编译期间无网络访问:依赖项在构建 Docker 镜像层中安装;build.sh 仅获取固定的源代码归档。

可重现性

构建过程_基本_可重现,但并非完全封闭:

  • nginx 源代码版本和 SHA256 在解压前已固定并验证。
  • NJS 版本和 SHA256 在解压前已固定并验证。
  • 构建依赖项在 Dockerfile.build 中列举,但未固定版本。
  • Debian 运行时包在构建时从实时 bookworm 仓库解析,因此不同构建之间次要版本可能发生漂移。

为提高可重现性,请固定基础镜像摘要:```bash docker pull debian:bookworm-slim docker inspect debian:bookworm-slim --format='{{index .RepoDigests 0}}'

Then use: FROM debian:bookworm-slim@sha256:

---

## CVE 修复详情

### CVE-2024-6119 - OpenSSL 版本升级

| 字段                | 值                                                |
| -------------------- | ---------------------------------------------------- |
| **组件**        | OpenSSL / libssl3                                    |
| **严重性**         | 高 (CVSS 7.5)                                      |
| **类型**             | 通过 X.509 名称检查导致的拒绝服务              |
| **基线版本** | 3.0.11-1~deb12u2                                     |
| **修复版本**    | 3.0.14-1~deb12u2 (或更高)                          |
| **我们的版本**      | 3.0.20-1~deb12u1                                     |
| **NVD**              | https://nvd.nist.gov/vuln/detail/CVE-2024-6119       |
| **公告**         | https://openssl-library.org/news/secadv/20240903.txt |

**修复工作原理:**

`.deb` 包声明了 `Depends: libssl3 (>= 3.0.14)`,这强制 `apt-get install` 拉取包含修复的 OpenSSL 版本。当前 Debian bookworm 仓库提供了 3.0.20,它修复了 CVE-2024-6119 以及从基线版本起的数十个其他 OpenSSL CVE(CVE-2024-2511, CVE-2024-5535, CVE-2024-4741, CVE-2023-5678, CVE-2023-6129, CVE-2023-6237, CVE-2024-9143, CVE-2025-15467, CVE-2025-69420)。

**扫描器行为:** Grype 和 Trivy 会在 dpkg 数据库中看到 `libssl3 3.0.20`,并识别到 3.0.20 ≥ 3.0.14,因此不再报告 CVE-2024-6119。无需 VEX——版本升级是不言自明的。

**验证:**```bash
grep "CVE-2024-6119" baseline-grype.txt  # present
grep "CVE-2024-6119" fixed-grype.txt     # absent

CVE-2026-42945 - 回传补丁

字段值
组件nginx ngx_http_rewrite_module
严重性中等(nginx.org 分类)
基准版本nginx 1.25.5
修复版本nginx 1.30.1(发布于 2026-05-13)
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-42945
安全公告https://my.f5.com/manage/s/article/K000161019
上游变更nginx 1.30.1 CHANGES:"重写模块中的堆内存缓冲区溢出"

漏洞:

src/http/ngx_http_script.c 中的 ngx_http_script_regex_end_code() 在处理重写正则表达式结果时,未能重置 e->is_args。如果 is_args 被前一个脚本引擎操作设置,则后续重定向/重写路径中的缓冲区长度计算将不正确,导致通过精心构造的请求 URI 造成攻击者可控制大小的堆内存缓冲区溢出。

修复(一行):```c // Added before the existing e->quote = 0; at line 1205 e->is_args = 0;

**补丁来源:**
下载工具