[CLSA-2026:1788695192] Fix CVE(s): CVE-2022-43548
Type:
security
Severity:
Important
Release date:
2026-09-06 11:46:43 UTC
Description:
* SECURITY UPDATE: --inspect DNS rebinding via permissive IP validation - debian/patches/CVE-2022-43548.patch: rewrite the inspector's IsIPAddress() to parse IPv4 (dotted-decimal only) and bracketed IPv6 hosts with uv_inet_pton(), rejecting octal, hexadecimal and leading-zero octet formats and treating 0.0.0.0/8 and ::/128 as non-routable, so a Host header IP that a browser resolves differently can no longer bypass the inspector host allow-list (backport of nodejs/node 2b433af094, with follow-up 73fa9ab7a5 folded in so the IPv6 string terminator is written inside the INET6_ADDRSTRLEN buffer) - CVE-2022-43548
CVEs fixed:
Updated packages:
  • alt-nodejs12-docs_12.22.12-28_amd64.deb
    sha:e498433e47207b965a96de4e12e2fce0bd586709
  • alt-nodejs12-nodejs_12.22.12-28_amd64.deb
    sha:4e9807ab0ac58ba0e7af5186e207c32884d0eeba
  • alt-nodejs12-nodejs-devel_12.22.12-28_amd64.deb
    sha:59f0358cc554f4e8fa11090e5cd69cacbf4f9576
  • alt-nodejs12-npm_6.14.16-12.22.12.28_amd64.deb
    sha:05bc89acb3151afb58d90a262c0aba108bb606b1
  • alt-nodejs12-docs_12.22.12-28_arm64.deb
    sha:00d6130f14923812b87cf7db23a9a9e0b94bfbfc
  • alt-nodejs12-nodejs_12.22.12-28_arm64.deb
    sha:76d0cf5627e209be9b1f1d6345e4864fe87367dd
  • alt-nodejs12-nodejs-devel_12.22.12-28_arm64.deb
    sha:3823218376729f611c95f582638a7bdf1e39e688
  • alt-nodejs12-npm_6.14.16-12.22.12.28_arm64.deb
    sha:913c3bb0773c147f24917a7bb0b420acfdab5269
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.