Opened 9 months ago

Closed 9 months ago

Last modified 8 months ago

#22638 closed enhancement (fixed)

node.js-22.22.0

Reported by: zeckma Owned by: zeckma
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New minor version.

Change History (5)

comment:1 by zeckma, 9 months ago

This is a security release. I'll adjust this pretty soon here.

comment:2 by zeckma, 9 months ago

Priority: normal → high

Security Fixes

  • CVE-2025-55130 (High): Bypass File System Permissions using crafted symlinks
  • CVE-2025-55131 (High): Timeout-based race conditions make Uint8Array/Buffer.alloc non-zerofilled
  • CVE-2025-55132 (Low): fs.futimes() Bypasses Read-Only Permission Model
  • CVE-2025-59465 (High): Node.js HTTP/2 server crashes with unhandled error when receiving malformed HEADERS frame
  • CVE-2025-59466 (Medium): Uncatchable "Maximum call stack size exceeded" error on Node.js via async_hooks leads to process crashes bypassing error handlers
  • CVE-2026-21637 (Medium): Node.js permission model bypass via unchecked Unix Domain Socket connections (UDS)

Information was obtained from ​https://nodejs.org/en/blog/vulnerability/december-2025-security-releases.

Other fixes

  • deps: update c-ares to v1.34.6
  • deps: update undici to 6.23.0
Last edited 9 months ago by zeckma (previous) (diff)

comment:3 by zeckma, 9 months ago

Fixed at 66c2c4beea36d9379e327c56fdcbd5b4a9209b88. Leaving open for SA.

comment:4 by zeckma, 9 months ago

Resolution: → fixed
Status: assigned → closed

SA-12.4-071 issued.

comment:5 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.