[CLSA-2026:1770904937] Fix CVE(s): CVE-2025-59466, CVE-2026-21637
Type:
security
Severity:
Important
Release date:
2026-02-12 14:02:22 UTC
Description:
* SECURITY UPDATE: Stack overflow exception handling in async_hooks - debian/patches/CVE-2025-59466.patch: rethrow stack overflow exceptions in async_hooks instead of calling FatalException - CVE-2025-59466 * SECURITY UPDATE: TLS callback exception handling vulnerability - debian/patches/CVE-2026-21637.patch: route pskCallback exceptions through error handlers to prevent remote attackers from crashing TLS servers - CVE-2026-21637
Updated packages:
  • alt-nodejs14-docs_14.21.3-18_amd64.deb
    sha:6a32b5335e06ed04dcd14d38a2c14ae0bf89a24d
  • alt-nodejs14-nodejs_14.21.3-18_amd64.deb
    sha:19cf098869934d977d3ae82f4fd93b2d6523cad5
  • alt-nodejs14-nodejs-devel_14.21.3-18_amd64.deb
    sha:9ed84a74b124f892bf5d7dc0ac0bc0c280326e1a
  • alt-nodejs14-npm_6.14.18-14.21.3-18_amd64.deb
    sha:1e6d342922d13e5128655207b7ec3d1bc7e9eee4
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.