[CLSA-2025:1759506795] Fix CVE(s): CVE-2025-23166
Type:
security
Severity:
Important
Release date:
2025-10-03 15:53:21 UTC
Description:
* SECURITY UPDATE: Node.js SignTraits::DeriveBits() remote crash vulnerability - debian/patches/CVE-2025-23166.patch: fix incorrect ThrowException() call in background thread to prevent process crash - CVE-2025-23166
Updated packages:
  • alt-nodejs18-docs_18.20.8-1+tuxcare.els1_amd64.deb
    sha:d9e8e62548069e5eeccf70b4787fc83c828ac202
  • alt-nodejs18-nodejs_18.20.8-1+tuxcare.els1_amd64.deb
    sha:e55c9979b3d84b5fd38e49c18c0eec3fa14d1c4a
  • alt-nodejs18-nodejs-devel_18.20.8-1+tuxcare.els1_amd64.deb
    sha:9a24773e73b0223598c7f1d98f43b75b9598f8f0
  • alt-nodejs18-npm_10.8.2-18.20.8.1_amd64.deb
    sha:c9e5ad94e90f88f68812f808621c2dfba3871d1c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.