Release date:
2026-08-31 13:41:49 UTC
Description:
* SECURITY UPDATE: HTTPS identity check not bound to connection or TLS
session reuse (incomplete fix for CVE-2026-48934)
- debian/patches/CVE-2026-58040.patch: tag request options in
https.request() with a per-request kPerRequestCheckServerIdentity symbol
when the caller supplies its own checkServerIdentity and the Agent was
not constructed with one, key Agent.prototype.getName() on that tag,
skip both the TLS session resume and the session caching listener in
createConnection() for tagged requests, and add an
Agent.prototype.keepSocketAlive() override in lib/https.js that refuses
to park such a socket in freeSockets
- CVE-2026-58040
Updated packages:
-
alt-nodejs20-docs_20.20.2-8_amd64.deb
sha:d40b0faaf96f085060c0d02a1f4a2dbe856bfeeb
-
alt-nodejs20-nodejs_20.20.2-8_amd64.deb
sha:c7eb5e99b15809b880521f6f5a9dd7126072c7e4
-
alt-nodejs20-nodejs-devel_20.20.2-8_amd64.deb
sha:f300ff91461a4032c6fa1e838d9eed2584035785
-
alt-nodejs20-npm_10.8.2-20.20.2-8_amd64.deb
sha:9347b70dcaf227a431065ae1d2c58f3fc13e5032
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.