[CLSA-2026:1770140451] nodejs: Fix of CVE-2025-23166
Type:
security
Severity:
Important
Release date:
2026-02-03 17:40:55 UTC
Description:
- CVE-2025-23166: fix SignTraits::DeriveBits() to properly validate user-supplied inputs to prevent crashing Node.js process
Updated packages:
  • nodejs-16.20.2-8.el9_6.tuxcare.els1.x86_64.rpm
    sha:0b6bb17bc446d04c5f31ed44b200b4e016ff367855be43a5b64ac1857728af7a
  • nodejs-devel-16.20.2-8.el9_6.tuxcare.els1.x86_64.rpm
    sha:8e78656a85e4ddf56ece51755ce2d326836b1e9b80a8102b0f3dddae9806ec0c
  • nodejs-docs-16.20.2-8.el9_6.tuxcare.els1.noarch.rpm
    sha:09c31792b4a284c860e860ecf185aa9f35f257b705951f0b442fce92d27e7d6c
  • nodejs-full-i18n-16.20.2-8.el9_6.tuxcare.els1.x86_64.rpm
    sha:ae8b0e1467f8f19125da88044bb63b2aa70e2937512044d4da058d9ed180a1a9
  • nodejs-libs-16.20.2-8.el9_6.tuxcare.els1.i686.rpm
    sha:84231843d5f249e34a8474317cc55a3552a36414624e9cd55a167f3dbfc7d5b6
  • nodejs-libs-16.20.2-8.el9_6.tuxcare.els1.x86_64.rpm
    sha:1cc4b71029e7a720610caa2dc46769473d86706efe0487c313ac13fa2cfa9f6f
  • npm-8.19.4_1.16.20.2-8.el9_6.tuxcare.els1.x86_64.rpm
    sha:c2d387ae8315cd314bb9767f2c349b9a094067de83da3f54f97ecd8d65d75fcf
  • v8-devel-9.4.146.26_1.16.20.2-8.el9_6.tuxcare.els1.x86_64.rpm
    sha:87e390f26516bfc6c98d26b3f00b91e71dcd169fd913ee937e9a9bd1baf62011
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.