ALAS2023-2026-2141


Amazon Linux 2023 Security Advisory: ALAS2023-2026-2141
Advisory Released Date: 2026-09-14
Advisory Updated Date: 2026-09-14
Severity: Medium

Issue Overview:

Versions of the package pacote from 11.2.7 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function's regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process. (CVE-2026-9496)


Affected Packages:

nodejs24


Issue Correction:
Run dnf update nodejs24 --releasever 2023.12.20260914 or dnf update --advisory ALAS2023-2026-2141 --releasever 2023.12.20260914 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    nodejs24-full-i18n-24.20.0-1.amzn2023.0.1.aarch64
    nodejs24-libs-debuginfo-24.20.0-1.amzn2023.0.1.aarch64
    nodejs24-libs-24.20.0-1.amzn2023.0.1.aarch64
    nodejs24-debuginfo-24.20.0-1.amzn2023.0.1.aarch64
    v8-13.6-devel-13.6.233.17-1.24.20.0.1.amzn2023.0.1.aarch64
    nodejs24-devel-24.20.0-1.amzn2023.0.1.aarch64
    nodejs24-24.20.0-1.amzn2023.0.1.aarch64
    nodejs24-debugsource-24.20.0-1.amzn2023.0.1.aarch64

noarch:
    nodejs24-docs-24.20.0-1.amzn2023.0.1.noarch
    nodejs24-npm-11.19.0-1.24.20.0.1.amzn2023.0.1.noarch

src:
    nodejs24-24.20.0-1.amzn2023.0.1.src

x86_64:
    nodejs24-libs-debuginfo-24.20.0-1.amzn2023.0.1.x86_64
    nodejs24-full-i18n-24.20.0-1.amzn2023.0.1.x86_64
    v8-13.6-devel-13.6.233.17-1.24.20.0.1.amzn2023.0.1.x86_64
    nodejs24-debuginfo-24.20.0-1.amzn2023.0.1.x86_64
    nodejs24-devel-24.20.0-1.amzn2023.0.1.x86_64
    nodejs24-24.20.0-1.amzn2023.0.1.x86_64
    nodejs24-libs-24.20.0-1.amzn2023.0.1.x86_64
    nodejs24-debugsource-24.20.0-1.amzn2023.0.1.x86_64