Release date:
2026-09-28 08:01:36 UTC
Description:
- CVE-2026-56850: https: distinguish PFX object-array agent keys, so an
https.Agent pool name built from a `pfx` array of { buf, passphrase } objects
folds in each entry's certificate and passphrase instead of stringifying the
array to the literal `[object Object]`, which made every such array share one
pool entry and let a request reuse a keep-alive socket or a resumed TLS
session authenticated with a different client certificate
- CVE-2026-58042: dns: handle large resolveAny address replies, by sizing the
A and AAAA TTL buffers from the reply's ANCOUNT instead of a fixed 256
entries, so a dns.resolveAny() answer carrying more than 256 A records no
longer trips CHECK_EQ(naddrttls, a_count) and aborts the process
- CVE-2026-58045: zlib: throw on out-of-bounds write buffers, so a TypedArray
whose byteLength is spoofed with a getter makes the synchronous node:zlib
entry points raise a catchable RangeError (ERR_OUT_OF_RANGE) instead of
failing a CHECK in CompressionStream::Write() and aborting the process
Updated packages:
-
alt-nodejs16-nodejs-16.20.2-30.el9.x86_64.rpm
sha:c82b5a83118b1fe6e4ef9381ad54b36383f057440ee3151727a4f09e60a47f48
-
alt-nodejs16-nodejs-devel-16.20.2-30.el9.x86_64.rpm
sha:e24848f3dc89e8919cbd8d7f5e1779c3d0b7df2e7bc3e5cc3bdb29aa36a07bb0
-
alt-nodejs16-nodejs-docs-16.20.2-30.el9.noarch.rpm
sha:30e0f252e8f763b360ba813dbf1252ffb4444a0c19735b1636a6a2f421fc6770
-
alt-nodejs16-npm-8.19.4-16.20.2.30.el9.x86_64.rpm
sha:f60233a1ab78e481d60601d2a9ba8657cd97a28c9af4c907bb1e6b60baaad8d8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.