Amazon Linux 2 Security Advisory: ALAS2NGINX1-2025-009
Advisory Released Date: 2025-08-19
Advisory Updated Date: 2025-08-25
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP authentication process memory; as a result, the server side may leak arbitrary bytes sent in a request to the authentication server. This issue happens during the NGINX SMTP authentication process and requires the attacker to make preparations against the target system to extract the leaked data. The issue affects NGINX only if (1) it is built with the ngx_mail_smtp_module, (2) the smtp_auth directive is configured with method "none," and (3) the authentication server returns the "Auth-Wait" response header.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. (CVE-2025-53859)
Affected Packages:
nginx
Note:
This advisory is applicable to Amazon Linux 2 - Nginx1 Extra. Visit this page to learn more about Amazon Linux 2 (AL2) Extras and this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update nginx or yum update --advisory ALAS2NGINX1-2025-009 to update your system.
aarch64:
nginx-1.28.0-1.amzn2.0.2.aarch64
nginx-core-1.28.0-1.amzn2.0.2.aarch64
nginx-mod-http-geoip-1.28.0-1.amzn2.0.2.aarch64
nginx-mod-http-image-filter-1.28.0-1.amzn2.0.2.aarch64
nginx-mod-http-perl-1.28.0-1.amzn2.0.2.aarch64
nginx-mod-http-xslt-filter-1.28.0-1.amzn2.0.2.aarch64
nginx-mod-mail-1.28.0-1.amzn2.0.2.aarch64
nginx-mod-stream-1.28.0-1.amzn2.0.2.aarch64
nginx-mod-devel-1.28.0-1.amzn2.0.2.aarch64
nginx-debuginfo-1.28.0-1.amzn2.0.2.aarch64
noarch:
nginx-all-modules-1.28.0-1.amzn2.0.2.noarch
nginx-filesystem-1.28.0-1.amzn2.0.2.noarch
src:
nginx-1.28.0-1.amzn2.0.2.src
x86_64:
nginx-1.28.0-1.amzn2.0.2.x86_64
nginx-core-1.28.0-1.amzn2.0.2.x86_64
nginx-mod-http-geoip-1.28.0-1.amzn2.0.2.x86_64
nginx-mod-http-image-filter-1.28.0-1.amzn2.0.2.x86_64
nginx-mod-http-perl-1.28.0-1.amzn2.0.2.x86_64
nginx-mod-http-xslt-filter-1.28.0-1.amzn2.0.2.x86_64
nginx-mod-mail-1.28.0-1.amzn2.0.2.x86_64
nginx-mod-stream-1.28.0-1.amzn2.0.2.x86_64
nginx-mod-devel-1.28.0-1.amzn2.0.2.x86_64
nginx-debuginfo-1.28.0-1.amzn2.0.2.x86_64
2025-08-25: The severity of this advisory has been changed from medium to low.