[security - high] nodejs:22 security update

エラータID: AXSA:2026-1639:01

リリース日: 
2026/08/24 Monday - 21:00
題名: 
[security - high] nodejs:22 security update
影響のあるチャネル: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.

Security Fix(es):

* sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data (CVE-2026-11822)
* sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 (CVE-2026-11824)
* brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257)
* brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays (CVE-2026-69152)
* ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass (CVE-2026-69192)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-11822
SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.
CVE-2026-11824
SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.
CVE-2026-14257
brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count under the limit while making each result progressively longer, so total memory scales with both count and string length until the process hits a fatal, uncatchable out-of-memory error. About 7.5 KB of input ('{a,b}'.repeat(1500)) crashes a default Node.js process. Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch / glob brace patterns - can be crashed by a small request. Fixed in 5.0.8 by adding a maxLength option (default 4,000,000) that bounds accumulated output and intermediate arrays.
CVE-2026-69152
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.
CVE-2026-69192
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and getaddrinfo all decode a leading zero as octal. The library and the network stack therefore disagree about which host a string names. new Address4('012.0.0.1') reports correctForm() of 12.0.0.1 and isPrivate() of false, but fetch('http://012.0.0.1/') connects to 10.0.0.1. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, will classify an internal target as external and allow the request. The defect is in the parse gate rather than in any one classifier, so every consumer of Address4 inherits it: isPrivate(), isLoopback(), isLinkLocal(), isCGNAT(), isInSubnet(), isHostInSubnet(), and correctForm() are all computed from the mis-decoded octets. This issue is fixed in version 10.3.1.

Modularity name: "nodejs"
Stream name: "22"

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. nodejs-nodemon-3.1.14-2.module+el9+1186+3bf1cfb1.src.rpm
    MD5: 8982f778497c0898070efff5e33af50e
    SHA-256: b327ac91dd098d14a00c742976bd9331e5a7ced81a3e7a535ad9399dfe9a0459
    Size: 455.16 kB
  2. nodejs-packaging-2021.06-6.module+el9+1186+3bf1cfb1.src.rpm
    MD5: 3a74fdb704c64a878a17a6029c219f73
    SHA-256: 63f4c6b3506117df55348a8771b82e5618414bf855490d79ea164af0abecd389
    Size: 25.40 kB
  3. nodejs-22.23.1-3.module+el9+1186+3bf1cfb1.src.rpm
    MD5: 1a5c3f675bf830d0ebc7da5bd761e1ac
    SHA-256: 5a6016925af70e908de044bff9379d60c4aabef63cfa49bbf57f1c6aa148db4d
    Size: 92.45 MB

Asianux Server 9 for x86_64
  1. nodejs-22.23.1-3.module+el9+1186+3bf1cfb1.x86_64.rpm
    MD5: b49faa50d8f5fc26efcd87f305f9afc1
    SHA-256: d9c805716e31db7fb71794fa20383b54b7f7913e8e2dde654e81080171b90327
    Size: 2.18 MB
  2. nodejs-debugsource-22.23.1-3.module+el9+1186+3bf1cfb1.x86_64.rpm
    MD5: 0870d7357ecc51bfbb6fa3eb32980d5a
    SHA-256: 20f9e402bbb367988d20651fa78643fa96af669c662483e04958ce2e8337d4b2
    Size: 18.07 MB
  3. nodejs-devel-22.23.1-3.module+el9+1186+3bf1cfb1.x86_64.rpm
    MD5: acb4334ba0f46243eb90c9adb6c84d86
    SHA-256: 7215d2a09de85e2b0cff2bf77279b521c774b32173e25c03f84d403c8084eeaa
    Size: 277.20 kB
  4. nodejs-docs-22.23.1-3.module+el9+1186+3bf1cfb1.noarch.rpm
    MD5: 46524803e61337a7832f43e86fe1e96b
    SHA-256: 3c14707828627224991ac7ae73f0adad5abcfa16c02f179f5e2a9c1d3b9e0ec5
    Size: 9.24 MB
  5. nodejs-full-i18n-22.23.1-3.module+el9+1186+3bf1cfb1.x86_64.rpm
    MD5: b982462328a4f59ca9ce8198234ee338
    SHA-256: e8d566c49ad3b3acfd94d7b0f107790d0f652b27c5f8c3b88b06d8d01a4203b6
    Size: 8.87 MB
  6. nodejs-libs-22.23.1-3.module+el9+1186+3bf1cfb1.x86_64.rpm
    MD5: fee5947b49e7744b3b2def61b08d8d22
    SHA-256: c47413289c92e887b4f67acf9d6398dde09c180a0c8272989395c0c538efb6e8
    Size: 20.55 MB
  7. nodejs-nodemon-3.1.14-2.module+el9+1186+3bf1cfb1.noarch.rpm
    MD5: abaa6cd88efc7285a80f2557348f1f61
    SHA-256: f3d70d271263db810a8d08f662186337fa3ccedfd4af014e4ce356886a8df758
    Size: 373.86 kB
  8. nodejs-packaging-2021.06-6.module+el9+1186+3bf1cfb1.noarch.rpm
    MD5: 937f0106d2720d6e9cf5aebf7183a65a
    SHA-256: 4b31d829eca1555a1bea2aa81dc8c71a2b5857beeb472c11823c61b512033b49
    Size: 18.66 kB
  9. nodejs-packaging-bundler-2021.06-6.module+el9+1186+3bf1cfb1.noarch.rpm
    MD5: 440ebe10fdce3c147cfae679b81762a7
    SHA-256: 6eaa5c7d954d83e8fe661d90e9e507a3fa9ad27d06c4dd5284214bf7d09cd809
    Size: 8.46 kB
  10. npm-10.9.8-1.22.23.1.3.module+el9+1186+3bf1cfb1.x86_64.rpm
    MD5: ca59635c9748f0702063c41a47521034
    SHA-256: 24101d2beabda4551b4e0b7f94e5a211159a3e087080b5f9fec04e51fa696151
    Size: 2.37 MB
  11. v8-12.4-devel-12.4.254.21-1.22.23.1.3.module+el9+1186+3bf1cfb1.x86_64.rpm
    MD5: da8f5b5c239f38c7503f0756379f8052
    SHA-256: 70ec55001ac0a6cd9e87556d5bd258f13c57bf9bb4513a056c3f1b7427ef4585
    Size: 16.23 kB