Release Info

Advisory: CLSA-2025:1764607118

OS: Debian 13

Public date: 2025-12-01 16:38:40.547973

Project: nodejs

Version: 14.21.3-9

Errata link: https://errata.tuxcare.com/els_alt_nodejs/debian13/CLSA-2025-1764607118.html

Changelog

* SECURITY UPDATE: Node.js policy integrity check bypass vulnerability - debian/patches/CVE-2023-38552.patch: use tamper-proof integrity check function to prevent tampering with Hash class internals in policy mechanism - CVE-2023-38552

Update

Update command: apt-get update apt-get --only-upgrade install alt-nodejs*

Packages list

alt-nodejs14-docs_14.21.3-9_amd64.deb alt-nodejs14-nodejs_14.21.3-9_amd64.deb alt-nodejs14-nodejs-devel_14.21.3-9_amd64.deb alt-nodejs14-npm_6.14.18-14.21.3.9_amd64.deb

CVEs

CVE-2023-38552