[CLSA-2026:1788185158] Fix CVE(s): CVE-2026-58040
Type:
security
Severity:
Moderate
Release date:
2026-08-31 14:06:10 UTC
Description:
* SECURITY UPDATE: HTTPS identity check not bound to connection or TLS session reuse (incomplete fix for CVE-2026-48934) - debian/patches/CVE-2026-58040.patch: tag request options in https.request() with a per-request kPerRequestCheckServerIdentity symbol when the caller supplies its own checkServerIdentity and the Agent was not constructed with one, key Agent.prototype.getName() on that tag, skip both the TLS session resume and the session caching listener in createConnection() for tagged requests, and add an Agent.prototype.keepSocketAlive() override in lib/https.js that refuses to park such a socket in freeSockets - CVE-2026-58040
CVEs fixed:
Updated packages:
  • alt-nodejs20-docs_20.20.2-8_amd64.deb
    sha:1ec2aaaedb61f82b70a2c2f0a8d7caaecdaadc7b
  • alt-nodejs20-nodejs_20.20.2-8_amd64.deb
    sha:a847159b9a85af84c225f702b7bfb74333d89699
  • alt-nodejs20-nodejs-devel_20.20.2-8_amd64.deb
    sha:1d3598ce8e568c188b86374b85e2c3adfa502ba8
  • alt-nodejs20-npm_10.8.2-20.20.2-8_amd64.deb
    sha:f0f27cd6e8df7ee8fa3af4046662b62a09849462
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.