[security - high] nodejs:24 security update

エラータID: AXSA:2026-1641:01

リリース日: 
2026/08/24 Monday - 21:43
題名: 
[security - high] nodejs:24 security update
影響のあるチャネル: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.

Security Fix(es):

* sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data (CVE-2026-11822)
* sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 (CVE-2026-11824)
* brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257)
* ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification (CVE-2026-54272)
* brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays (CVE-2026-69152)
* ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass (CVE-2026-69192)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-11822
SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.
CVE-2026-11824
SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.
CVE-2026-14257
brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count under the limit while making each result progressively longer, so total memory scales with both count and string length until the process hits a fatal, uncatchable out-of-memory error. About 7.5 KB of input ('{a,b}'.repeat(1500)) crashes a default Node.js process. Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch / glob brace patterns - can be crashed by a small request. Fixed in 5.0.8 by adding a maxLength option (default 4,000,000) that bounds accumulated output and intermediate arrays.
CVE-2026-54272
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. Address6.getType() classifies an address by matching it against a table of known IPv6 special-use prefixes, returning Global unicast when nothing matches. That table had no entry for the IPv4-mapped range (::ffff:0:0/96), so every mapped address fell through to Global unicast; NAT64 addresses matched their own NAT64 … labels. The boolean checks isLoopback, isUnspecified, and isMulticast compared getType() against a fixed label and so returned false, while isLinkLocal and isULA checked only the native IPv6 ranges. The library already exposed isMapped4() and to4(), but did not apply them inside these checks, so a mapped or NAT64 address was never normalized to its embedded IPv4 address before classification. For IPv4-mapped addresses the host OS routes to the IPv4 stack, so the misclassification is reachable on any dual-stack host. For NAT64, the classification bypass is unconditional but end-to-end reachability additionally requires a NAT64/DNS64 gateway in the deployment network.This issue has been fixed in version 10.2.1.
CVE-2026-69152
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.
CVE-2026-69192
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and getaddrinfo all decode a leading zero as octal. The library and the network stack therefore disagree about which host a string names. new Address4('012.0.0.1') reports correctForm() of 12.0.0.1 and isPrivate() of false, but fetch('http://012.0.0.1/') connects to 10.0.0.1. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, will classify an internal target as external and allow the request. The defect is in the parse gate rather than in any one classifier, so every consumer of Address4 inherits it: isPrivate(), isLoopback(), isLinkLocal(), isCGNAT(), isInSubnet(), isHostInSubnet(), and correctForm() are all computed from the mis-decoded octets. This issue is fixed in version 10.3.1.

Modularity name: "nodejs"
Stream name: "24"

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. nodejs-nodemon-3.1.14-3.module+el9+1185+25921f54.src.rpm
    MD5: 4a1e8934e13bfd5e1cd6f24d045c2016
    SHA-256: a9682c499e6d2291fee6fa9aac7dc0ee56b2e81765bfde433a3c69cc8be09fbd
    Size: 462.94 kB
  2. nodejs-packaging-2021.06-6.module+el9+1185+25921f54.src.rpm
    MD5: 6f5d1a0f2e26c56bd380df777aba4993
    SHA-256: 6d3ad6a5fc71f1a9481856a74f2e0f0789750021ec85d2b1bf953694a976d113
    Size: 25.41 kB
  3. nodejs-24.18.0-6.module+el9+1185+25921f54.src.rpm
    MD5: 653c586087336cfbf1e1e8772f8a3350
    SHA-256: 8a459f169c21df03c4f5b111aba29bb2b75a272d08fa0de87a22c50551d019bb
    Size: 98.92 MB

Asianux Server 9 for x86_64
  1. nodejs-24.18.0-6.module+el9+1185+25921f54.x86_64.rpm
    MD5: 5e39fe0f79091a174ee832bdb1dfced1
    SHA-256: cb4d32677ace6d1687193ff0095a3f38b5f2715ca3dbac1859f29cd238f07e06
    Size: 67.65 kB
  2. nodejs-debugsource-24.18.0-6.module+el9+1185+25921f54.x86_64.rpm
    MD5: f0b315750dd854d0e2b5b343e83a29b6
    SHA-256: fa5de564056acfd7f161d735aa78a2e72189a1ead9308e76772abcaddd3cce8e
    Size: 19.37 MB
  3. nodejs-devel-24.18.0-6.module+el9+1185+25921f54.x86_64.rpm
    MD5: 543738dd70f11aae984d9e587ca4483c
    SHA-256: 7de168e3b19ce78c46839c0f29318158072257c62aa45dc95a6218ed177a5a0a
    Size: 333.82 kB
  4. nodejs-docs-24.18.0-6.module+el9+1185+25921f54.noarch.rpm
    MD5: 11f5e3da48bf9df37232c96299da28d7
    SHA-256: e04eb1494814d45c3831d36bd448008f8ad38de3f4b6ad2fe395b80929301f16
    Size: 5.07 MB
  5. nodejs-full-i18n-24.18.0-6.module+el9+1185+25921f54.x86_64.rpm
    MD5: 488e529de30265053a649d4a93799541
    SHA-256: f9dac9470a65b09ffc247d7d9312cea3418c75e3b1c804c1d8b0ab2b4526409e
    Size: 8.87 MB
  6. nodejs-libs-24.18.0-6.module+el9+1185+25921f54.x86_64.rpm
    MD5: f352ef3b90b7c812ae3f2694bdf98475
    SHA-256: 06635283d3136029a8f4fc984eb4a5305c92bac79837fdcbf06b51254b41a14c
    Size: 18.47 MB
  7. nodejs-nodemon-3.1.14-3.module+el9+1185+25921f54.noarch.rpm
    MD5: b08a01af0753306f94260cb255ef554b
    SHA-256: 532967faf025c1bd2af0be022b1fed973e732b566ac7eafb1da9ab1f0b063fb8
    Size: 375.96 kB
  8. nodejs-packaging-2021.06-6.module+el9+1185+25921f54.noarch.rpm
    MD5: 101f2d0418009aad2215a6d61bf53610
    SHA-256: d47c0157c5961f6fa28e523147b2abc076341ffdbe36b204bc76c2724fdcdb8a
    Size: 18.66 kB
  9. nodejs-packaging-bundler-2021.06-6.module+el9+1185+25921f54.noarch.rpm
    MD5: 655c4d729b5b5ae9e7ee0ef562867534
    SHA-256: c358657764741d12bdc9c385df124f6659a921cca3a69182e7e23aaf40b09d41
    Size: 8.47 kB
  10. npm-11.16.0-1.24.18.0.6.module+el9+1185+25921f54.noarch.rpm
    MD5: c3d4e5cf781c2758a427108efd98c1fe
    SHA-256: f62c6a4e72bfaeac4741dbf3b35ba30e63393d6caefd14abd6ac0cbf2b736827
    Size: 2.49 MB
  11. v8-13.6-devel-13.6.233.17-1.24.18.0.6.module+el9+1185+25921f54.x86_64.rpm
    MD5: c34f578f60135e730850c06a11de205d
    SHA-256: 5560da1c3cdc6b77d2613610d992a1059a13619ad2fbf03b1236573c8226c799
    Size: 33.82 kB