nginx:1.25-bookworm 的源构建即插即用替换一个源构建的 nginx 1.25.5 容器镜像,它修复了官方 nginx:1.25-bookworm 镜像中存在的两个 CVE,同时保留了上游运行时行为。
| CVE | 组件 | 严重程度 | 技术 | 验证模型 |
|---|---|---|---|---|
| CVE-2024-6119 | OpenSSL / libssl3 | 高 | 依赖版本升级 | 扫描器可验证:libssl3 3.0.20 在 dpkg 数据库中可见 |
| CVE-2026-42945 | nginx ngx_http_rewrite_module | 严重 | 向后移植源补丁 | 来源可验证:补丁推导 + 回归测试 + 构建证明 + VEX |
这两种代表了两种不同的修复模型:
此镜像的 nginx -V 配置参数匹配 nginx:1.25-bookworm(在规范化 -ffile-prefix-map 构建路径后逐字符比较;在 test/compat.py::test_nginx_version 中验证)。测试套件(make test)针对实时上游镜像验证了 89 个断言,涵盖镜像元数据、动态模块、文件系统布局、入口点行为、dpkg 打包和 HTTP 请求处理。
与上游的已知差异(未经验证为相同):
nginx -V 中的 built with OpenSSL X.X.X 行反映构建者的 libssl-dev 版本,可能不同于上游编译时的 OpenSSL。debian:bookworm-slim,而非官方镜像继承的包树。libssl3 版本是 bookworm 当前提供的版本(撰写时为 3.0.20),而非上游镜像中固定的版本。make image
make test
make test-cve
make verify-patch
make scan
一个命令用于构建、测试和扫描:```bash
make all
build/ Dockerfile.build Builder image (debian:bookworm-slim + compilation deps) build.sh Fetch → verify → patch → compile → package nginx generate-vex.sh Generate OpenVEX document for backported CVE verify-patch.sh Re-derive patch from upstream tarballs (audit tool) patches/ CVE-2026-42945.patch Backported one-line fix from nginx 1.30.1 CVE-2026-42945.provenance.json Machine-readable patch provenance and derivation metadata
test/ compat.py 89-assertion compatibility test suite (runs against live upstream) test_cve_2026_42945.py CVE-specific regression test (exercises vulnerable code path)
artifacts/
patch-attestation.json Build-time patch attestation (tracked)
nginx_*.deb Compiled package (gitignored - rebuilt via make build-source)
nginx Compiled binary (gitignored)
Containerfile Final runtime image definition
Makefile Orchestrates build → test → scan pipeline
vex.json Generated OpenVEX v0.2.0 document
baseline-trivy.txt Point-in-time Trivy scan of nginx:1.25-bookworm
baseline-grype.txt Point-in-time Grype scan of nginx:1.25-bookworm
fixed-trivy.txt Trivy scan of the fixed image
fixed-grype.txt Grype scan of the fixed image (without VEX)
fixed-grype-vex.txt Grype scan of the fixed image (with VEX applied)
---
## 构建过程
### 架构```
debian:bookworm-slim (builder)
└─ build.sh
├─ curl nginx-1.25.5.tar.gz (SHA256-verified)
├─ curl njs-0.8.4 from github.com/nginx/njs
├─ patch -p1 < CVE-2026-42945.patch
├─ ./configure (flags identical to upstream nginx -V)
├─ make: release binary, debug binary, 4 dynamic module families (×2 release/debug)
├─ make: NJS modules (×2 release/debug) + njs CLI binary
└─ dpkg-deb → nginx_1.25.5-1~bookworm+echo1_<arch>.deb
debian:bookworm-slim (runtime)
├─ apt-get install runtime deps (libssl3 ≥ 3.0.14 enforced)
├─ dpkg -i nginx_*.deb
└─ COPY --from=upstream /docker-entrypoint.sh + /docker-entrypoint.d/
The Containerfile does NOT copy /etc/nginx from upstream. All configuration
files are shipped inside the .deb and tracked by dpkg's conffile mechanism.
This is required for the 10-listen-on-ipv6-by-default.sh entrypoint script,
which uses dpkg-query to detect whether default.conf has been user-modified.
./configure && make。无上游二进制文件,不使用 apt install nginx。build.sh 仅获取固定的源代码归档。构建过程_基本_可重现,但并非完全封闭:
Dockerfile.build 中列举,但未固定版本。为提高可重现性,请固定基础镜像摘要:```bash docker pull debian:bookworm-slim docker inspect debian:bookworm-slim --format='{{index .RepoDigests 0}}'
---
## CVE 修复详情
### CVE-2024-6119 - OpenSSL 版本升级
| 字段 | 值 |
| -------------------- | ---------------------------------------------------- |
| **组件** | OpenSSL / libssl3 |
| **严重性** | 高 (CVSS 7.5) |
| **类型** | 通过 X.509 名称检查导致的拒绝服务 |
| **基线版本** | 3.0.11-1~deb12u2 |
| **修复版本** | 3.0.14-1~deb12u2 (或更高) |
| **我们的版本** | 3.0.20-1~deb12u1 |
| **NVD** | https://nvd.nist.gov/vuln/detail/CVE-2024-6119 |
| **公告** | https://openssl-library.org/news/secadv/20240903.txt |
**修复工作原理:**
`.deb` 包声明了 `Depends: libssl3 (>= 3.0.14)`,这强制 `apt-get install` 拉取包含修复的 OpenSSL 版本。当前 Debian bookworm 仓库提供了 3.0.20,它修复了 CVE-2024-6119 以及从基线版本起的数十个其他 OpenSSL CVE(CVE-2024-2511, CVE-2024-5535, CVE-2024-4741, CVE-2023-5678, CVE-2023-6129, CVE-2023-6237, CVE-2024-9143, CVE-2025-15467, CVE-2025-69420)。
**扫描器行为:** Grype 和 Trivy 会在 dpkg 数据库中看到 `libssl3 3.0.20`,并识别到 3.0.20 ≥ 3.0.14,因此不再报告 CVE-2024-6119。无需 VEX——版本升级是不言自明的。
**验证:**```bash
grep "CVE-2024-6119" baseline-grype.txt # present
grep "CVE-2024-6119" fixed-grype.txt # absent
| 字段 | 值 |
|---|---|
| 组件 | nginx ngx_http_rewrite_module |
| 严重性 | 中等(nginx.org 分类) |
| 基准版本 | nginx 1.25.5 |
| 修复版本 | nginx 1.30.1(发布于 2026-05-13) |
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-42945 |
| 安全公告 | https://my.f5.com/manage/s/article/K000161019 |
| 上游变更 | nginx 1.30.1 CHANGES:"重写模块中的堆内存缓冲区溢出" |
漏洞:
src/http/ngx_http_script.c 中的 ngx_http_script_regex_end_code() 在处理重写正则表达式结果时,未能重置 e->is_args。如果 is_args 被前一个脚本引擎操作设置,则后续重定向/重写路径中的缓冲区长度计算将不正确,导致通过精心构造的请求 URI 造成攻击者可控制大小的堆内存缓冲区溢出。
修复(一行):```c // Added before the existing e->quote = 0; at line 1205 e->is_args = 0;
**补丁来源:**