Release date:
2026-08-31 13:58:14 UTC
Description:
* SECURITY UPDATE: HTTPS identity check not bound to connection or TLS
session reuse (incomplete fix for CVE-2026-48934)
- debian/patches/CVE-2026-58040.patch: tag request options in
https.request() with a per-request kPerRequestCheckServerIdentity symbol
when the caller supplies its own checkServerIdentity and the Agent was
not constructed with one, key Agent.prototype.getName() on that tag,
skip both the TLS session resume and the session caching listener in
createConnection() for tagged requests, and add an
Agent.prototype.keepSocketAlive() override in lib/https.js that refuses
to park such a socket in freeSockets
- CVE-2026-58040
Updated packages:
-
alt-nodejs20-docs_20.20.2-8_amd64.deb
sha:34019589288bb6ef3bcaa409bf23e555e2b549a8
-
alt-nodejs20-nodejs_20.20.2-8_amd64.deb
sha:99b4e557e33f1032065dda64bdcdfe932792a0ce
-
alt-nodejs20-nodejs-devel_20.20.2-8_amd64.deb
sha:29a96ed269bc6be2863da800bfffc39b503ca4d2
-
alt-nodejs20-npm_10.8.2-20.20.2-8_amd64.deb
sha:1e00cedeccc10133224ef4b5e3c7c3c12e935df8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.