[CLSA-2026:1788694943] alt-nodejs12-nodejs: Fix of CVE-2022-43548
Type:
security
Severity:
Important
Release date:
2026-09-06 11:42:33 UTC
Description:
- CVE-2022-43548: harden the inspector IsIPAddress() to parse IPv4 and bracketed IPv6 hosts with uv_inet_pton(), rejecting octal, hexadecimal and leading-zero octet formats and treating 0.0.0.0/8 and ::/128 as non-routable, closing the --inspect DNS-rebinding host allow-list bypass - Folded in upstream follow-up 73fa9ab7a5, which keeps the IPv6 string terminator inside the INET6_ADDRSTRLEN buffer
CVEs fixed:
Updated packages:
  • alt-nodejs12-nodejs-12.22.12-31.el10.x86_64.rpm
    sha:007d1dd8c7368decdc371aa05da46089dd4c0b246fa150fc8c6f38338feed235
  • alt-nodejs12-nodejs-devel-12.22.12-31.el10.x86_64.rpm
    sha:7365d58babf69b2b3670ae3c8c4e6285b806f7268857bfbf442c9927c61ff948
  • alt-nodejs12-nodejs-docs-12.22.12-31.el10.noarch.rpm
    sha:fc740df43e5db73c839373dac9f54bf4e41557ca1e83356f69532ae3c92bbf64
  • alt-nodejs12-npm-6.14.16-12.22.12.31.el10.x86_64.rpm
    sha:4ca26724bc1a2b251c6f7ff38e0554891f7fbab8c7534131b2950160ce042d1b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.