Release date:
2026-09-28 08:13:06 UTC
Description:
* SECURITY UPDATE: https.Agent socket-pool names built from a `pfx` array of
{ buf, passphrase } objects collapse to the literal `[object Object]`, so
requests configured with different mTLS client certificates share one pool
entry and can reuse each other's authenticated socket or TLS session
(CVE-2026-56850)
- debian/patches/CVE-2026-56850.patch: add getPfxAgentKey() to
lib/https.js and route the `pfx` leg of Agent.prototype.getName()
through it, so an array-valued `pfx` contributes each entry's raw
certificate buffer and its effective passphrase to the pool name; a
non-array `pfx` keeps the name it had. Also adds the upstream
regression tests test/parallel/test-https-agent-getname.js (new
assertions) and test/parallel/test-https-agent-pfx-object-array-reuse.js
- CVE-2026-56850
* SECURITY UPDATE: dns.resolveAny() aborts the process when a DNS reply
carries more than 256 A records, which a hostile or merely large
authoritative answer can trigger repeatedly for a denial of service
(CVE-2026-58042)
- debian/patches/CVE-2026-58042.patch: in src/cares_wrap.cc, replace the
fixed ares_addrttl[256] / ares_addr6ttl[256] TTL buffers with
std::vectors sized from the reply's ANCOUNT via the new
GetAnswerCountForTTLBuffer() and MakeAddrTTLBuffer() helpers, so
naddrttls can no longer come back clamped below the record count and
trip CHECK_EQ(naddrttls, a_count); also adds the regression test
test/parallel/test-dns-resolveany-ttl-overflow.js
- CVE-2026-58042
* SECURITY UPDATE: the synchronous node:zlib entry points abort the process
when handed a TypedArray whose byteLength is spoofed with a getter, which
can be repeated for a denial of service (CVE-2026-58045)
- debian/patches/CVE-2026-58045.patch: in src/node_zlib.cc, turn the two
CHECK(Buffer::IsWithinBounds(...)) assertions in
CompressionStream::Write() into THROW_ERR_OUT_OF_RANGE() so an
out-of-bounds input or output buffer raises a catchable RangeError with
code ERR_OUT_OF_RANGE instead of aborting; also adds the upstream
regression assertions to test/parallel/test-zlib-invalid-input.js
- CVE-2026-58045
Updated packages:
-
alt-nodejs14-docs_14.21.3-32_amd64.deb
sha:92c094ab6847d0024f53b9e4ebc86803bccdbf30
-
alt-nodejs14-nodejs_14.21.3-32_amd64.deb
sha:aece9a28f3cf231adcb05dcbbf1cabcfa50b664f
-
alt-nodejs14-nodejs-devel_14.21.3-32_amd64.deb
sha:976daad870c76169578bf43dc3b9a2849ce8ab4e
-
alt-nodejs14-npm_6.14.18-14.21.3-32_amd64.deb
sha:dfd9cc68ed02b58a1e9254a3f6862a750ab38f7f
-
alt-nodejs14-docs_14.21.3-32_arm64.deb
sha:fee63db47f8e92a333e0da77566bde6f82ae7e32
-
alt-nodejs14-nodejs_14.21.3-32_arm64.deb
sha:fa0daec39db1b317d09b083760bf77d0ed11e8c2
-
alt-nodejs14-nodejs-devel_14.21.3-32_arm64.deb
sha:a31f32e12f5818b1ac2bb2a2b8cd1878e12da027
-
alt-nodejs14-npm_6.14.18-14.21.3-32_arm64.deb
sha:c8e2da09dca074ac34f3d668e365ad1feb9a8e6e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.