[CLSA-2026:1788186026] Fix CVE(s): CVE-2026-58040
Type:
security
Severity:
Moderate
Release date:
2026-08-31 14:20:37 UTC
Description:
* SECURITY UPDATE: HTTPS identity check not bound to connection or TLS session reuse (incomplete fix for CVE-2026-48934) - debian/patches/CVE-2026-58040.patch: tag request options in https.request() with a per-request kPerRequestCheckServerIdentity symbol when the caller supplies its own checkServerIdentity and the Agent was not constructed with one, key Agent.prototype.getName() on that tag, skip both the TLS session resume and the session caching listener in createConnection() for tagged requests, and add an Agent.prototype.keepSocketAlive() override in lib/https.js that refuses to park such a socket in freeSockets - CVE-2026-58040
CVEs fixed:
Updated packages:
  • alt-nodejs20-docs_20.20.2-8_amd64.deb
    sha:34019589288bb6ef3bcaa409bf23e555e2b549a8
  • alt-nodejs20-nodejs_20.20.2-8_amd64.deb
    sha:2c39af86a5820bf627a244e0222985aa8be4d020
  • alt-nodejs20-nodejs-devel_20.20.2-8_amd64.deb
    sha:29a96ed269bc6be2863da800bfffc39b503ca4d2
  • alt-nodejs20-npm_10.8.2-20.20.2-8_amd64.deb
    sha:7b99b92271106eda56da3fdc14b70f077dfbc9bd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.