[CLSA-2026:1770708014] alt-nodejs14-nodejs: Fix of CVE-2025-55131
Type:
security
Severity:
Important
Release date:
2026-02-10 07:20:18 UTC
Description:
- CVE-2025-55131: refactor unsafe buffer creation to remove zero-fill toggle mechanism that could expose uninitialized memory when using vm module with timeout options, preventing potential information disclosure
Updated packages:
  • alt-nodejs14-nodejs-14.21.3-18.el8.x86_64.rpm
    sha:18a61f5cfe5da3ead125bbfdbefc8123d4a2a2144aedd5507e1e9057bbcc02cf
  • alt-nodejs14-nodejs-devel-14.21.3-18.el8.x86_64.rpm
    sha:69bda840abdc0c59ce7b85ee32c4414d7c65928ea73bf1ec3189417491df1dde
  • alt-nodejs14-nodejs-docs-14.21.3-18.el8.noarch.rpm
    sha:afd917f8b552d27ea2f7a92df7c5dfab9247dd4c3825fcec02863a9de341ad5e
  • alt-nodejs14-npm-6.14.18-14.21.3.18.el8.x86_64.rpm
    sha:a48346a28af37ee32595cbd349c566ca9c26ab0f7885cd5be0909524cbd875ad
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.