Release date:
2026-06-12 08:48:43 UTC
Description:
* SECURITY UPDATE: experimental policy bypass via mainModule.__proto__
- debian/patches/CVE-2023-30581.patch: install the policy-aware require()
on the module prototype and assign process.mainModule via
setOwnProperty(), so process.mainModule.__proto__.require() can no
longer escape the --experimental-policy manifest restrictions
- CVE-2023-30581
* SECURITY UPDATE: HTTP/2 Rapid Reset denial of service
- debian/patches/CVE-2023-44487.patch: backport the upstream nghttp2
1.57.0 RST_STREAM token-bucket rate limiter to the bundled nghttp2
1.42.0 (default burst=1000, rate=33/s); excessive incoming RST_STREAM
frames now tear the connection down with GOAWAY instead of doing
unbounded per-stream work
- CVE-2023-44487
Updated packages:
-
alt-nodejs14-docs_14.21.3-24_amd64.deb
sha:46df7ed75a2702245e11374875655d67e731425f
-
alt-nodejs14-nodejs_14.21.3-24_amd64.deb
sha:e01a8a81fac4e3e7b0ea9378df620549fcd1b59f
-
alt-nodejs14-nodejs-devel_14.21.3-24_amd64.deb
sha:64d4c4636cc4ef988de57259415ea95e0bdc9909
-
alt-nodejs14-npm_6.14.18-14.21.3-24_amd64.deb
sha:a2eb8ec683088adb121cd43d1cd66f7054c8835e
-
alt-nodejs14-docs_14.21.3-24_arm64.deb
sha:aa632ad71aaaf61b3642f29ca094ee55c6bc1f1f
-
alt-nodejs14-nodejs_14.21.3-24_arm64.deb
sha:f45478d576be1c766603e0cacde33b1fd282225b
-
alt-nodejs14-nodejs-devel_14.21.3-24_arm64.deb
sha:59452462833fe0d2e99462d688becca0b2d8932d
-
alt-nodejs14-npm_6.14.18-14.21.3-24_arm64.deb
sha:0cff94555f73679cfb3468600ccdd831daa5463f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.