Amazon Linux 2023 Security Advisory: ALAS2023-2026-1403
Advisory Released Date: 2026-02-05
Advisory Updated Date: 2026-02-05
FAQs regarding Amazon Linux ALAS/CVE Severity
Bypass File System Permissions using crafted symlinks (CVE-2025-55130)
A flaw in Node.js's buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using the vm module with the timeout option. Under specific timing conditions, buffers allocated with Buffer.alloc and other TypedArray instances like Uint8Array may contain leftover data from previous operations, allowing in-process secrets like tokens or passwords to leak or causing data corruption.
While exploitation typically requires precise timing or in-process code execution, it can become remotely exploitable when untrusted input influences workload and timeouts, leading to potential confidentiality and integrity impact. (CVE-2025-55131)
fs.futimes() Bypasses Read-Only Permission Model (CVE-2025-55132)
Node.js HTTP/2 server crashes with unhandled error when receiving malformed HEADERS frame (CVE-2025-59465)
Uncatchable "Maximum call stack size exceeded" error on Node.js via async_hooks leads to process crashes bypassing error handlers (CVE-2025-59466)
TLS PSK/ALPN Callback Exceptions Bypass Error Handlers, Causing DoS and FD Leak
NOTE: https://nodejs.org/en/blog/vulnerability/december-2025-security-releases#tls-pskalpn-callback-exceptions-bypass-error-handlers-causing-dos-and-fd-leak-cve-2026-21637---medium (CVE-2026-21637)
Affected Packages:
nodejs22
Issue Correction:
Run dnf update nodejs22 --releasever 2023.10.20260202 or dnf update --advisory ALAS2023-2026-1403 --releasever 2023.10.20260202 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
aarch64:
nodejs22-libs-debuginfo-22.22.0-1.amzn2023.0.1.aarch64
nodejs22-devel-22.22.0-1.amzn2023.0.1.aarch64
nodejs22-debuginfo-22.22.0-1.amzn2023.0.1.aarch64
nodejs22-full-i18n-22.22.0-1.amzn2023.0.1.aarch64
v8-12.4-devel-12.4.254.21-1.22.22.0.1.amzn2023.0.1.aarch64
nodejs22-libs-22.22.0-1.amzn2023.0.1.aarch64
nodejs22-22.22.0-1.amzn2023.0.1.aarch64
nodejs22-npm-10.9.4-1.22.22.0.1.amzn2023.0.1.aarch64
nodejs22-debugsource-22.22.0-1.amzn2023.0.1.aarch64
noarch:
nodejs22-docs-22.22.0-1.amzn2023.0.1.noarch
src:
nodejs22-22.22.0-1.amzn2023.0.1.src
x86_64:
nodejs22-libs-debuginfo-22.22.0-1.amzn2023.0.1.x86_64
nodejs22-full-i18n-22.22.0-1.amzn2023.0.1.x86_64
nodejs22-libs-22.22.0-1.amzn2023.0.1.x86_64
v8-12.4-devel-12.4.254.21-1.22.22.0.1.amzn2023.0.1.x86_64
nodejs22-debuginfo-22.22.0-1.amzn2023.0.1.x86_64
nodejs22-devel-22.22.0-1.amzn2023.0.1.x86_64
nodejs22-22.22.0-1.amzn2023.0.1.x86_64
nodejs22-npm-10.9.4-1.22.22.0.1.amzn2023.0.1.x86_64
nodejs22-debugsource-22.22.0-1.amzn2023.0.1.x86_64