[CLSA-2026:1788699305] alt-nodejs12-nodejs: Fix of CVE-2022-43548
Type:
security
Severity:
Important
Release date:
2026-09-06 12:55:15 UTC
Description:
- CVE-2022-43548: harden the inspector IsIPAddress() to parse IPv4 and bracketed IPv6 hosts with uv_inet_pton(), rejecting octal, hexadecimal and leading-zero octet formats and treating 0.0.0.0/8 and ::/128 as non-routable, closing the --inspect DNS-rebinding host allow-list bypass - Folded in upstream follow-up 73fa9ab7a5, which keeps the IPv6 string terminator inside the INET6_ADDRSTRLEN buffer
CVEs fixed:
Updated packages:
  • alt-nodejs12-nodejs-12.22.12-31.el9.x86_64.rpm
    sha:aec3326c96cd70a42af6e9eb0afffd522d80a3da996760a9c1f8b6e10d1148a2
  • alt-nodejs12-nodejs-devel-12.22.12-31.el9.x86_64.rpm
    sha:ba2a9e15001b5bb5f46b26e06ba79ee26d14d97b6fbce8b63c7a70689522c08d
  • alt-nodejs12-nodejs-docs-12.22.12-31.el9.noarch.rpm
    sha:df9e2e4db382c9facacce153f72742def90f7d9e5a9e95a14a883d27b99b3124
  • alt-nodejs12-npm-6.14.16-12.22.12.31.el9.x86_64.rpm
    sha:5a7e8fe64e5cf17ca3519f99a51b13fffc4e78139bc6e5cdf446c1c004d22fe2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.