[CLSA-2025:1765365464] alt-nodejs16-nodejs: Fix of CVE-2023-46809
Type:
security
Severity:
Moderate
Release date:
2025-12-10 11:17:48 UTC
Description:
- CVE-2023-46809: fixes a timing‑side‑channel flaw in the RSA PKCS#1 v1.5 decryption logic, preventing a Marvin‑style padding‑oracle attack that could allow recovery of sensitive data.
Updated packages:
  • alt-nodejs16-nodejs-16.20.2-4.el9.x86_64.rpm
    sha:b16c705b097eebf7f88bf209912b6c12814118cba754954617c2f1aa7977de6b
  • alt-nodejs16-nodejs-devel-16.20.2-4.el9.x86_64.rpm
    sha:124439b4dcf1cb073b95e68fea2a3eaaa2a9f1ddbb4edf43f78a3ce86dde3495
  • alt-nodejs16-nodejs-docs-16.20.2-4.el9.noarch.rpm
    sha:bab05e8674a5fa6ec987344a20e5d03d8ddb09917e28f81b2f5ff41e21401a6e
  • alt-nodejs16-npm-8.19.4-16.20.2.4.el9.x86_64.rpm
    sha:d5d34e50a3cdf421ee4b35807890cd3b7e699cd297dc2cda7c38c507cee00aa1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.