[CLSA-2026:1788856058] alt-nodejs12-nodejs: Fix of CVE-2022-43548
Type:
security
Severity:
Important
Release date:
2026-09-08 08:27:47 UTC
Description:
- CVE-2022-43548: harden the inspector IsIPAddress() to parse IPv4 and bracketed IPv6 hosts with uv_inet_pton(), rejecting octal, hexadecimal and leading-zero octet formats and treating 0.0.0.0/8 and ::/128 as non-routable, closing the --inspect DNS-rebinding host allow-list bypass - Folded in upstream follow-up 73fa9ab7a5, which keeps the IPv6 string terminator inside the INET6_ADDRSTRLEN buffer
CVEs fixed:
Updated packages:
  • alt-nodejs12-nodejs-12.22.12-31.el6.x86_64.rpm
    sha:d204fb56a79d25727f2b56dec82dc8b9eb75ff0ae90e0799019b01c641d159ac
  • alt-nodejs12-nodejs-devel-12.22.12-31.el6.x86_64.rpm
    sha:38c7bff53d6b53f026488d984398e60b88ec83ad07838943feffef067f588320
  • alt-nodejs12-nodejs-docs-12.22.12-31.el6.noarch.rpm
    sha:b455f495a37f5ab870fd011b9f56f3801f13fc7a9addc253d8fee1e08f9b6164
  • alt-nodejs12-npm-6.14.16-12.22.12.31.el6.x86_64.rpm
    sha:c82a130eb8f965e106c07dd9640564fedc190fb7257ba32f4529bdc274a92916
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.