[CLSA-2025:1764177376] Fix of 10 CVEs
Type:
security
Severity:
Critical
Release date:
2025-11-26 17:16:21 UTC
Description:
* update version, add patches and logs for debian * SECURITY UPDATE: Node.js vulnerabilities - debian/patches/CVE-2023-30589.patch: fix llhttp parser to properly validate LF after CR in HTTP header fields, add lenient flag checks before allowing CR without LF, add test file to verify the fix prevents request smuggling attacks - CVE-2023-30589 - debian/patches/CVE-2023-32559.patch: disable process.binding() when policy is enabled; update deprecations and errors docs and add new tests ensuring denial behavior - CVE-2023-32559 - debian/patches/CVE-2023-30590.patch: update documentation and add tests clarifying DH generateKeys behavior - CVE-2023-30590 - debian/patches/CVE-2023-23918.patch: prevent process.mainModule.require() policy bypass - CVE-2023-23918 - debian/patches/CVE-2023-32002-32006.patch: fix policy bypass vulnerabilities in experimental policy mechanism: * CVE-2023-32002: prevent Module.constructor._load() bypass by adding constructor property protection * CVE-2023-32006: prevent require.main.constructor and require.extensions bypass by implementing secure module loading validation - CVE-2023-32002, CVE-2023-32006 - debian/patches/CVE-2024-25629.patch: fix ares__read_line() function to prevent out-of-bounds read when parsing configuration files with embedded NULL characters - CVE-2024-25629 - debian/patches/CVE-2024-28863.patch: prevent extraction in excessively deep sub-folders to address unlimited sub-folders vulnerability - CVE-2024-28863 - debian/patches/CVE-2025-23085.patch: fix HTTP/2 memory leak on premature socket close or invalid header (ERR_PROTO) - CVE-2025-23085 - debian/patches/CVE-2024-27983.patch: close HTTP/2 streams during session destruction to prevent memory leak and DoS - CVE-2024-27983
Updated packages:
  • alt-nodejs12-docs_12.22.12-5_amd64.deb
    sha:c5c01323b304a7b260597d7b7fea3f5befda03ff
  • alt-nodejs12-nodejs_12.22.12-5_amd64.deb
    sha:4c0db95ddd3f1c344a0fed0178dad8668c46f12c
  • alt-nodejs12-nodejs-devel_12.22.12-5_amd64.deb
    sha:c61f38d8eab2592fbab5c11e1f8ec6c7534f046a
  • alt-nodejs12-npm_6.14.16-12.22.12.5_amd64.deb
    sha:028c85dc19159de44f724844f5533b1687935e5c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.