Amazon Linux 2023 Security Advisory: ALAS2023-2026-2141
Advisory Released Date: 2026-09-14
Advisory Updated Date: 2026-09-14
Severity:
Medium
Issue Overview:
Versions of the package pacote from 11.2.7 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function's regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process. (CVE-2026-9496)
Affected Packages:
nodejs24
Issue Correction:
Run dnf update nodejs24 --releasever 2023.12.20260914 or dnf update --advisory ALAS2023-2026-2141 --releasever 2023.12.20260914 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
New Packages:
aarch64:
nodejs24-full-i18n-24.20.0-1.amzn2023.0.1.aarch64
nodejs24-libs-debuginfo-24.20.0-1.amzn2023.0.1.aarch64
nodejs24-libs-24.20.0-1.amzn2023.0.1.aarch64
nodejs24-debuginfo-24.20.0-1.amzn2023.0.1.aarch64
v8-13.6-devel-13.6.233.17-1.24.20.0.1.amzn2023.0.1.aarch64
nodejs24-devel-24.20.0-1.amzn2023.0.1.aarch64
nodejs24-24.20.0-1.amzn2023.0.1.aarch64
nodejs24-debugsource-24.20.0-1.amzn2023.0.1.aarch64
noarch:
nodejs24-docs-24.20.0-1.amzn2023.0.1.noarch
nodejs24-npm-11.19.0-1.24.20.0.1.amzn2023.0.1.noarch
src:
nodejs24-24.20.0-1.amzn2023.0.1.src
x86_64:
nodejs24-libs-debuginfo-24.20.0-1.amzn2023.0.1.x86_64
nodejs24-full-i18n-24.20.0-1.amzn2023.0.1.x86_64
v8-13.6-devel-13.6.233.17-1.24.20.0.1.amzn2023.0.1.x86_64
nodejs24-debuginfo-24.20.0-1.amzn2023.0.1.x86_64
nodejs24-devel-24.20.0-1.amzn2023.0.1.x86_64
nodejs24-24.20.0-1.amzn2023.0.1.x86_64
nodejs24-libs-24.20.0-1.amzn2023.0.1.x86_64
nodejs24-debugsource-24.20.0-1.amzn2023.0.1.x86_64