Release date:
2026-09-25 16:50:04 UTC
Description:
- CVE-2026-56850: https: distinguish PFX object-array agent keys, so an
https.Agent pool name built from a `pfx` array of { buf, passphrase } objects
folds in each entry's certificate and passphrase instead of stringifying the
array to the literal `[object Object]`, which made every such array share one
pool entry and let a request reuse a keep-alive socket or a resumed TLS
session authenticated with a different client certificate
- CVE-2026-58042: dns: handle large resolveAny address replies, by sizing the
A and AAAA TTL buffers from the reply's ANCOUNT instead of a fixed 256
entries, so a dns.resolveAny() answer carrying more than 256 A records no
longer trips CHECK_EQ(naddrttls, a_count) and aborts the process
- CVE-2026-58045: zlib: throw on out-of-bounds write buffers, so a TypedArray
whose byteLength is spoofed with a getter makes the synchronous node:zlib
entry points raise a catchable RangeError (ERR_OUT_OF_RANGE) instead of
failing a CHECK in CompressionStream::Write() and aborting the process
Updated packages:
-
alt-nodejs20-nodejs-20.20.2-13.el10.x86_64.rpm
sha:187ad7be02f7d23bc6914c9a40410e3c43097d66f4f9984f46a31a4b418a5bbb
-
alt-nodejs20-nodejs-devel-20.20.2-13.el10.x86_64.rpm
sha:df126ea6f80678f3c5aa8b4b70e9f99691234011d74620159ec6554fda0a45d4
-
alt-nodejs20-nodejs-docs-20.20.2-13.el10.noarch.rpm
sha:5ea86ddd91da5b3d7b34a2cd912f124778ea140ef4964bb2f88964f71fd7a143
-
alt-nodejs20-npm-10.8.2-20.20.2.13.el10.x86_64.rpm
sha:b51cb2b4ced055eb4993bd66d49ce4df12d7e86545b16e627dc0b8f2a9084f10
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.