[CLSA-2026:1790354049] alt-nodejs12-nodejs: Fix of 3 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-25 16:34:21 UTC
Description:
- CVE-2026-56850: https: distinguish PFX object-array agent keys, so an https.Agent pool name built from a `pfx` array of { buf, passphrase } objects folds in each entry's certificate and passphrase instead of stringifying the array to the literal `[object Object]`, which made every such array share one pool entry and let a request reuse a keep-alive socket or a resumed TLS session authenticated with a different client certificate - CVE-2026-58042: dns: handle large resolveAny address replies, by sizing the A and AAAA TTL buffers from the reply's ANCOUNT instead of a fixed 256 entries, so a dns.resolveAny() answer carrying more than 256 A records no longer trips CHECK_EQ(naddrttls, a_count) and aborts the process - CVE-2026-58045: zlib: throw on out-of-bounds write buffers, so a TypedArray whose byteLength is spoofed with a getter makes the synchronous node:zlib entry points raise a catchable RangeError (ERR_OUT_OF_RANGE) instead of failing a CHECK in CompressionStream::Write() and aborting the process
Updated packages:
  • alt-nodejs12-nodejs-12.22.12-33.el6.x86_64.rpm
    sha:b0e247c7653989c9268e9f9588f436c0ce8de287cb3493e4d5fb56645ae0e2e3
  • alt-nodejs12-nodejs-devel-12.22.12-33.el6.x86_64.rpm
    sha:ff3cdfe8b9ec13e73dfda7a309b23ebdc2652e11f64f243083dd4daa5a210d7e
  • alt-nodejs12-nodejs-docs-12.22.12-33.el6.noarch.rpm
    sha:3da3ba65f5a0878103b0e67a38386498e41c5f05f3fc4fb676c4ff2102823cb6
  • alt-nodejs12-npm-6.14.16-12.22.12.33.el6.x86_64.rpm
    sha:9fd2cf3fb0fb5b29dc919a0d4e6d39d9eb6feedd27668930cadac81b0b2a4558
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.