[CLSA-2025:1759506490] Fix CVE(s): CVE-2025-23166
Type:
security
Severity:
Important
Release date:
2025-10-03 15:48:15 UTC
Description:
* SECURITY UPDATE: Node.js SignTraits::DeriveBits() remote crash vulnerability - debian/patches/CVE-2025-23166.patch: fix incorrect ThrowException() call in background thread to prevent process crash - CVE-2025-23166
Updated packages:
  • alt-nodejs18-docs_18.20.8-1+tuxcare.els1_amd64.deb
    sha:bc173db46fcc3e6a845f0a4e13298b8a679d603e
  • alt-nodejs18-nodejs_18.20.8-1+tuxcare.els1_amd64.deb
    sha:8bc99acb65d0556aadb447bd93d018c850d13849
  • alt-nodejs18-nodejs-devel_18.20.8-1+tuxcare.els1_amd64.deb
    sha:550699a5976988acb94cf86e83320c54e4636cfb
  • alt-nodejs18-npm_10.8.2-18.20.8.1_amd64.deb
    sha:916cdda3951df01af3c814cbb9de354142bf017b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.