[CLSA-2026:1770646095] Fix CVE(s): CVE-2025-59466, CVE-2026-21637
Type:
security
Severity:
Important
Release date:
2026-02-09 14:08:20 UTC
Description:
* SECURITY UPDATE: TLS callback exception handling vulnerability - debian/patches/CVE-2026-21637.patch: wrap pskCallback and ALPNCallback invocations in try-catch blocks to route exceptions through error handlers - CVE-2026-21637 * SECURITY UPDATE: Stack overflow exception handling in async_hooks - debian/patches/CVE-2025-59466.patch: rethrow stack overflow exceptions in async_hooks instead of calling FatalException - CVE-2025-59466
Updated packages:
  • alt-nodejs23-docs_23.11.1-4_amd64.deb
    sha:865d227e7d0e7261d4071cb68914caea8fec0a08
  • alt-nodejs23-nodejs_23.11.1-4_amd64.deb
    sha:ebe25f434173182e250bd89885910a57ab246c04
  • alt-nodejs23-nodejs-devel_23.11.1-4_amd64.deb
    sha:c45a7b57a170580791047f32164661be5a366860
  • alt-nodejs23-npm_10.9.2-23.11.1.4_amd64.deb
    sha:7006a48acb4e9d9870a5873efde796b79ce2d3f8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.