[CLSA-2026:1790591334] Fix CVE(s): CVE-2026-56850, CVE-2026-58042, CVE-2026-58045
Type:
security
Severity:
Moderate
Release date:
2026-09-28 10:29:08 UTC
Description:
* SECURITY UPDATE: https.Agent socket-pool names built from a `pfx` array of { buf, passphrase } objects collapse to the literal `[object Object]`, so requests configured with different mTLS client certificates share one pool entry and can reuse each other's authenticated socket or TLS session (CVE-2026-56850) - debian/patches/CVE-2026-56850.patch: add getPfxAgentKey() to lib/https.js and route the `pfx` leg of Agent.prototype.getName() through it, so an array-valued `pfx` contributes each entry's raw certificate buffer and its effective passphrase to the pool name; a non-array `pfx` keeps the name it had. Also adds the upstream regression tests test/parallel/test-https-agent-getname.js (new assertions) and test/parallel/test-https-agent-pfx-object-array-reuse.js - CVE-2026-56850 * SECURITY UPDATE: dns.resolveAny() aborts the process when a DNS reply carries more than 256 A records, which a hostile or merely large authoritative answer can trigger repeatedly for a denial of service (CVE-2026-58042) - debian/patches/CVE-2026-58042.patch: in src/cares_wrap.cc, replace the fixed ares_addrttl[256] / ares_addr6ttl[256] TTL buffers with std::vectors sized from the reply's ANCOUNT via the new GetAnswerCountForTTLBuffer() and MakeAddrTTLBuffer() helpers, so naddrttls can no longer come back clamped below the record count and trip CHECK_EQ(naddrttls, a_count); also adds the regression test test/parallel/test-dns-resolveany-ttl-overflow.js - CVE-2026-58042 * SECURITY UPDATE: the synchronous node:zlib entry points abort the process when handed a TypedArray whose byteLength is spoofed with a getter, which can be repeated for a denial of service (CVE-2026-58045) - debian/patches/CVE-2026-58045.patch: in src/node_zlib.cc, turn the two CHECK(Buffer::IsWithinBounds(...)) assertions in CompressionStream::Write() into THROW_ERR_OUT_OF_RANGE() so an out-of-bounds input or output buffer raises a catchable RangeError with code ERR_OUT_OF_RANGE instead of aborting; also adds the upstream regression assertions to test/parallel/test-zlib-invalid-input.js - CVE-2026-58045
Updated packages:
  • alt-nodejs16-docs_16.20.2-28_amd64.deb
    sha:5507b2da87f058bf72cca762108d39c37640083b
  • alt-nodejs16-nodejs_16.20.2-28_amd64.deb
    sha:afb65542ac845c1e8beda496f3af7703b4ed123f
  • alt-nodejs16-nodejs-devel_16.20.2-28_amd64.deb
    sha:9c84a5afdc9dbfcd6ef40f96c444effc4711992f
  • alt-nodejs16-npm_8.19.4-16.20.2-28_amd64.deb
    sha:cd155259e3a359e9df4312b8e5ec695969478de7
  • alt-nodejs16-docs_16.20.2-28_arm64.deb
    sha:e55fe91aaacf93e5691824b4f9edb8e880338b4b
  • alt-nodejs16-nodejs_16.20.2-28_arm64.deb
    sha:49c8c71e528f7d6f56e0a0409197665e6df3b986
  • alt-nodejs16-nodejs-devel_16.20.2-28_arm64.deb
    sha:eb5eabf21e07791b58ce34526f6fbf8260de26ed
  • alt-nodejs16-npm_8.19.4-16.20.2-28_arm64.deb
    sha:9e8f2491bd0a58e00d3d3338eb74e02e63330b19
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.