[CLSA-2026:1770708208] alt-nodejs14-nodejs: Fix of CVE-2025-55131
Type:
security
Severity:
Important
Release date:
2026-02-10 07:23:31 UTC
Description:
- CVE-2025-55131: refactor unsafe buffer creation to remove zero-fill toggle mechanism that could expose uninitialized memory when using vm module with timeout options, preventing potential information disclosure
Updated packages:
  • alt-nodejs14-nodejs-14.21.3-18.el7.x86_64.rpm
    sha:bf405b4737c8aaaca806133e1fafb5d9e5d2282055100e213ebbdbbf72c07389
  • alt-nodejs14-nodejs-devel-14.21.3-18.el7.x86_64.rpm
    sha:a88f9930a95f680c9c969d2ef4b102fc8c42f193b19457c5bc0478b01283618e
  • alt-nodejs14-nodejs-docs-14.21.3-18.el7.noarch.rpm
    sha:113b9ee57281e960de6db5f10e305efd83bb6407ffd81af3e48199f1e7b95a48
  • alt-nodejs14-npm-6.14.18-14.21.3.18.el7.x86_64.rpm
    sha:6df0ce8cdc947d99c3262cec0097e0b0b9d7957d25a5875c3d175e46e42e20cd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.