Release date:
2026-06-01 07:48:18 UTC
Description:
* SECURITY UPDATE: HashDoS via V8 array-index hash collisions
- debian/patches/CVE-2026-21717.patch: scramble V8 array-index hash_field
with a 3-round xorshift-multiply so consecutive numeric strings no
longer hash to consecutive buckets, preventing O(n^2) HashDoS via
JSON.parse
- CVE-2026-21717
Updated packages:
-
alt-nodejs12-docs_12.22.12-21_amd64.deb
sha:8f405faf4cae52a145570c680da5c2ee07f7b8ad
-
alt-nodejs12-nodejs_12.22.12-21_amd64.deb
sha:f7c1cf0d5b8d4dc7dbb25f3795fe3cb04def1168
-
alt-nodejs12-nodejs-devel_12.22.12-21_amd64.deb
sha:8a9950692bce4c12ee22dd2e6810b7e36063bfd5
-
alt-nodejs12-npm_6.14.16-12.22.12.21_amd64.deb
sha:ec1fc9a38642d325f0d9722406c9b5b552c6a390
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.