Opened 6 months ago

Closed 6 months ago

#23036 closed enhancement (fixed)

node.js-24.14.1

Reported by: Bruce Dubbs Owned by: zeckma
Priority: high Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (7)

comment:1 by Douglas R. Reno, 6 months ago

Priority: normal → high

Release notes can be found at ​https://nodejs.org/en/blog/release/v22.22.2

Security vulnerabilities:

(CVE-2026-21637) wrap SNICallback invocation in try/catch (Matteo Collina) - High
(CVE-2026-21710) use null prototype for headersDistinct/trailersDistinct (Matteo Collina) - High
(CVE-2026-21713) use timing-safe comparison in Web Cryptography HMAC (Filip Skokan) - Medium
(CVE-2026-21714) handle NGHTTP2_ERR_FLOW_CONTROL error code (RafaelGSS) - Medium
(CVE-2026-21717) test array index hash collision (Joyee Cheung) - Medium
(CVE-2026-21715) add permission check to realpath.native (RafaelGSS) - Low
(CVE-2026-21716) include permission check on lib/fs/promises (RafaelGSS) - Low

comment:2 by Joe Locash, 6 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

Before I update the book I'm wondering why dev isn't on 24.14? It is the latest active LTS release.

comment:3 by Bruce Dubbs, 6 months ago

Summary: node.js-22.22.2 → node.js-24.14.1

What the currency script is doing right now is looking explicitly for the latest v22 version. There are v22, v23, v24, and v25 (and older) entries at ​https://nodejs.org/dist/.

Right now I see: v24.14.1 Latest LTS and v25.8.2 Latest Release

I see that Arch is currently at v25.8.2, but that would probably interfere with the esr version of FF that we use.

I'll update the currency to use the latest LTS release and we should use v24.14.1 for now.

comment:4 by Joe Locash, 6 months ago

This is a security release.
Notable Changes

    (CVE-2026-21710) use null prototype for headersDistinct/trailersDistinct (Matteo Collina) - High
    (CVE-2026-21637) wrap SNICallback invocation in try/catch (Matteo Collina) - High
    (CVE-2026-21717) test array index hash collision (Joyee Cheung) - Medium
    (CVE-2026-21713) use timing-safe comparison in Web Cryptography HMAC and KMAC (Filip Skokan) - Medium
    (CVE-2026-21714) handle NGHTTP2_ERR_FLOW_CONTROL error code (RafaelGSS) - Medium
    (CVE-2026-21712) handle url crash on different url formats (RafaelGSS) - Medium
    (CVE-2026-21716) include permission check on lib/fs/promises (RafaelGSS) - Low
    (CVE-2026-21715) add permission check to realpath.native (RafaelGSS) - Low

Fixed at fae12a7e6d.

Leaving open for SA.

comment:5 by zeckma, 6 months ago

Owner: changed from Joe Locash to zeckma
Status: assigned → new

I'll handle the SA.

comment:6 by zeckma, 6 months ago

Status: new → assigned

comment:7 by Douglas R. Reno, 6 months ago

Resolution: → fixed
Status: assigned → closed

SA-13.0-030 issued

Note: See TracTickets for help on using tickets.