[CLSA-2026:1788699541] alt-nodejs12-nodejs: Fix of CVE-2022-43548
Type:
security
Severity:
Important
Release date:
2026-09-06 12:59:11 UTC
Description:
- CVE-2022-43548: harden the inspector IsIPAddress() to parse IPv4 and bracketed IPv6 hosts with uv_inet_pton(), rejecting octal, hexadecimal and leading-zero octet formats and treating 0.0.0.0/8 and ::/128 as non-routable, closing the --inspect DNS-rebinding host allow-list bypass - Folded in upstream follow-up 73fa9ab7a5, which keeps the IPv6 string terminator inside the INET6_ADDRSTRLEN buffer
CVEs fixed:
Updated packages:
  • alt-nodejs12-nodejs-12.22.12-31.el8.x86_64.rpm
    sha:d001f346e03146c8a14dfadd2024da39a69f6a92e76cc705e8fea24ee234883c
  • alt-nodejs12-nodejs-devel-12.22.12-31.el8.x86_64.rpm
    sha:7548323c9651161e789ec07175f4a5951a21bf80c3f22d2ec24417ef76389d8f
  • alt-nodejs12-nodejs-docs-12.22.12-31.el8.noarch.rpm
    sha:fa874d568bcd9705dcdee38e84b3f5270f3d02f1995cee6a31e2bbfe9785de25
  • alt-nodejs12-npm-6.14.16-12.22.12.31.el8.x86_64.rpm
    sha:a9e7d8cc7738ff1fd278ee3790b63c417077f1ae61bec0c0dd3eb37c7a6a9120
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.