Release date:
2026-09-06 11:38:51 UTC
Description:
- CVE-2022-43548: harden the inspector IsIPAddress() to parse IPv4 and bracketed
IPv6 hosts with uv_inet_pton(), rejecting octal, hexadecimal and leading-zero
octet formats and treating 0.0.0.0/8 and ::/128 as non-routable, closing the
--inspect DNS-rebinding host allow-list bypass
- Folded in upstream follow-up 73fa9ab7a5, which keeps the IPv6 string
terminator inside the INET6_ADDRSTRLEN buffer
Updated packages:
-
alt-nodejs12-nodejs-12.22.12-31.el7.x86_64.rpm
sha:c8aa94d38ccd08cdc8dca0effb8d4355190af07be35df775f75934fd9dac2ee1
-
alt-nodejs12-nodejs-devel-12.22.12-31.el7.x86_64.rpm
sha:cb3ef6f946ba7a28b0a0272eb06847e2d2e65dbe58f202efab5e55e84dddad95
-
alt-nodejs12-nodejs-docs-12.22.12-31.el7.noarch.rpm
sha:1735d58a8293b69442cfe71ef106c51916504de312e568e5bec573894d3a2386
-
alt-nodejs12-npm-6.14.16-12.22.12.31.el7.x86_64.rpm
sha:499931b5942447eb4efdaae8cdaf3ae4618e4a87912254508f593063213000b0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.