[CLSA-2026:1769775296] nodejs: Fix of 3 CVEs
Type:
security
Severity:
Low
Release date:
2026-01-30 14:55:09 UTC
Description:
- CVE-2025-59465: add default error handler to TLSSocket to prevent server crash when connection is abruptly destroyed during initialization - CVE-2025-59466: fix stack overflow exception handling in async_hooks to allow catching with try-catch instead of requiring uncaughtException handlers - CVE-2025-55131: refactor unsafe buffer creation to remove zero-fill toggle
Updated packages:
  • nodejs-16.20.2-3.el9_2.tuxcare.els15.x86_64.rpm
    sha:eb4c1c12420bf6193058d35e3d85aa19f0d94003a001e010eecfcff3d6fa6c23
  • nodejs-devel-16.20.2-3.el9_2.tuxcare.els15.x86_64.rpm
    sha:fe1beb1b489e27ec84928541b4f90cd0f81b93d23770c8c4660db6044b8074db
  • nodejs-docs-16.20.2-3.el9_2.tuxcare.els15.noarch.rpm
    sha:ad47240299037ee4c02243e688e16aa434192e953aa362cf8ac3ff88e1dfa09b
  • nodejs-full-i18n-16.20.2-3.el9_2.tuxcare.els15.x86_64.rpm
    sha:5ca6e2aefdae3853758cbd0e6c6d6ce740d7b2e46bda89afe96547b60ef9b3e4
  • nodejs-libs-16.20.2-3.el9_2.tuxcare.els15.i686.rpm
    sha:755b48a56aa2ec8c0b2d2128706951e275508825fc95fd512c7679f3bbcb4321
  • nodejs-libs-16.20.2-3.el9_2.tuxcare.els15.x86_64.rpm
    sha:ba8c3bf102f6b58fdc608d6cdc35f1946e409801f6503337c97a21550344148d
  • npm-8.19.4_1.16.20.2-3.el9_2.tuxcare.els15.x86_64.rpm
    sha:82a0ea805ff2b74df14b98ba0ccaab23f6927f1580b7d7ea40f79be328515336
  • v8-devel-9.4.146.26_1.16.20.2-3.el9_2.tuxcare.els15.x86_64.rpm
    sha:598bd850bd4f312b7af9dd42fd220fc202be938d95241436d9686844de773edd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.