ALAS2023-2026-1980


Amazon Linux 2023 Security Advisory: ALAS2023-2026-1980
Advisory Released Date: 2026-07-20
Advisory Updated Date: 2026-07-20
Severity: Important

Issue Overview:

A use-after-free / double-free in c-ares' query-completion handling. The
same flaw -- a query's callback being invoked while the query is still
linked in the channel's internal lookup structures -- is present at
multiple points in the resend/finish path (timeout handling, response
handling, and query dispatch). If the query, or for `ares_getaddrinfo()`
the owning `host_query`, is freed as a side effect of that callback, it
is then accessed and/or freed a second time. (CVE-2026-33630)


Affected Packages:

nodejs24


Issue Correction:
Run dnf update nodejs24 --releasever 2023.12.20260720 or dnf update --advisory ALAS2023-2026-1980 --releasever 2023.12.20260720 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    nodejs24-libs-debuginfo-24.18.0-1.amzn2023.0.2.aarch64
    nodejs24-debuginfo-24.18.0-1.amzn2023.0.2.aarch64
    nodejs24-full-i18n-24.18.0-1.amzn2023.0.2.aarch64
    v8-13.6-devel-13.6.233.17-1.24.18.0.1.amzn2023.0.2.aarch64
    nodejs24-24.18.0-1.amzn2023.0.2.aarch64
    nodejs24-libs-24.18.0-1.amzn2023.0.2.aarch64
    nodejs24-devel-24.18.0-1.amzn2023.0.2.aarch64
    nodejs24-debugsource-24.18.0-1.amzn2023.0.2.aarch64

noarch:
    nodejs24-docs-24.18.0-1.amzn2023.0.2.noarch
    nodejs24-npm-11.16.0-1.24.18.0.1.amzn2023.0.2.noarch

src:
    nodejs24-24.18.0-1.amzn2023.0.2.src

x86_64:
    nodejs24-libs-debuginfo-24.18.0-1.amzn2023.0.2.x86_64
    nodejs24-full-i18n-24.18.0-1.amzn2023.0.2.x86_64
    nodejs24-debuginfo-24.18.0-1.amzn2023.0.2.x86_64
    v8-13.6-devel-13.6.233.17-1.24.18.0.1.amzn2023.0.2.x86_64
    nodejs24-24.18.0-1.amzn2023.0.2.x86_64
    nodejs24-devel-24.18.0-1.amzn2023.0.2.x86_64
    nodejs24-libs-24.18.0-1.amzn2023.0.2.x86_64
    nodejs24-debugsource-24.18.0-1.amzn2023.0.2.x86_64