Release date:
2026-06-16 11:29:24 UTC
Description:
* SECURITY UPDATE: experimental policy bypass via mainModule.__proto__
- debian/patches/CVE-2023-30581.patch: set the policy-wrapped require on
Module.prototype and assign process.mainModule via setOwnProperty so
process.mainModule.__proto__.require() can no longer load modules not
declared in the policy manifest (backport of nodejs/node d0a8264ec9);
includes the upstream regression test in test/parallel/test-policy-manifest.js
adapted for node 12 (new policy-manifest fixtures)
- CVE-2023-30581
* SECURITY UPDATE: HTTP/2 Rapid Reset denial of service
- debian/patches/CVE-2023-44487.patch: backport the nghttp2 RST_STREAM
rate-limit mitigation into bundled deps/nghttp2 (token-bucket limiter,
default burst 1000 / rate 33, GOAWAY with INTERNAL_ERROR on exhaustion)
so rapidly reset HTTP/2 streams no longer exhaust server resources
(backport of nghttp2 72b4af6, shipped in nghttp2 1.57.0)
- CVE-2023-44487
Updated packages:
-
alt-nodejs12-docs_12.22.12-22_amd64.deb
sha:35d78fa3af66c916c4b04ec4af22634971be370d
-
alt-nodejs12-nodejs_12.22.12-22_amd64.deb
sha:9862cd703fc914f880c8c386393af6c70fb26e5f
-
alt-nodejs12-nodejs-devel_12.22.12-22_amd64.deb
sha:a9de8d2689ca0bf5d4e20748220ed1f9cad7216e
-
alt-nodejs12-npm_6.14.16-12.22.12.22_amd64.deb
sha:e32c7b076b8eb77bff8ed0b234e4ae84f40e2b71
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.