[CLSA-2026:1790582935] alt-nodejs16-nodejs: Fix of 3 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-28 08:09:07 UTC
Description:
- CVE-2026-56850: https: distinguish PFX object-array agent keys, so an https.Agent pool name built from a `pfx` array of { buf, passphrase } objects folds in each entry's certificate and passphrase instead of stringifying the array to the literal `[object Object]`, which made every such array share one pool entry and let a request reuse a keep-alive socket or a resumed TLS session authenticated with a different client certificate - CVE-2026-58042: dns: handle large resolveAny address replies, by sizing the A and AAAA TTL buffers from the reply's ANCOUNT instead of a fixed 256 entries, so a dns.resolveAny() answer carrying more than 256 A records no longer trips CHECK_EQ(naddrttls, a_count) and aborts the process - CVE-2026-58045: zlib: throw on out-of-bounds write buffers, so a TypedArray whose byteLength is spoofed with a getter makes the synchronous node:zlib entry points raise a catchable RangeError (ERR_OUT_OF_RANGE) instead of failing a CHECK in CompressionStream::Write() and aborting the process
Updated packages:
  • alt-nodejs16-nodejs-16.20.2-30.el10.x86_64.rpm
    sha:88fd1f0876981826ffc7ed0120b2504f45e3dd033be4ea1ad7ca1949e89ae6ee
  • alt-nodejs16-nodejs-devel-16.20.2-30.el10.x86_64.rpm
    sha:406387c4c5cc9ad8cb39ff55b1f75476ab02fd3b5a1c48ecc5184aa1edec2569
  • alt-nodejs16-nodejs-docs-16.20.2-30.el10.noarch.rpm
    sha:0e359ffc6bbf4176ffb7bcf99afde2c4f1a88c1b8a54210e989bd9d8672a5714
  • alt-nodejs16-npm-8.19.4-16.20.2.30.el10.x86_64.rpm
    sha:e4d5a60345f2e7770cad7f6ef72b1a3af3cd5b72fca6d865289816852b33aec4
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.