Back Linuxsecurity openSUSE Leap 15.5 nodejs20 Important Fix Multiple Issues 2026-0457
This update for nodejs20 fixes the following issues: * Update to 20.20.0: * CVE-2026-22036: Updated undici to 6.23.0 (bsc#1256848) * CVE-2025-59465: Add TLSSocket default error handler (bsc#1256573) * CVE-2025-55132: Disable futimes when permission model is enabled (bsc#1256571) * CVE-2025-55130: Require full read and write to symlink APIs (bsc#1256569) * CVE-2025-59466: Rethrow stack overflow exceptions in async_hooks (bsc#1256574) * CVE-2025-55131: Refactor unsafe buffer creation to remove zero-fill toggle (bsc#1256570) * CVE-2026-21637: Route callback exceptions through error handlers (bsc#1256576)
## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-457=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-457=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-457=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-457=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-457=1
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-457=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-457=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-457=1
zypper in -t patch SUSE-2026-457=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-457=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * nodejs20-debugsource-20.20.0-150500.11.24.1 * nodejs20-20.20.0-150500.11.24.1 * nodejs20-devel-20.20.0-150500.11.24.1 * nodejs20-debuginfo-20.20.0-150500.11.24.1 * npm20-20.20.0-150500.11.24.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * nodejs20-docs-20.20.0-150500.11.24.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * nodejs20-debugsource-20.20.0-150500.11.24.1 * nodejs20-20.20.0-150500.11.24.1 * nodejs20-devel-20.20.0-150500.11.24.1 * nodejs20-debuginfo-20.20.0-150500.11.24.1 * npm20-20.20.0-150500.11.24.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * nodejs20-docs-20.20.0-150500.11.24.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * nodejs20-debugsource-20.20.0-150500.11.24.1 * nodejs20-20.20.0-150500.11.24.1 * Read the Full Advisory
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
* nodejs20-debugsource-20.20.0-150500.11.24.1
* nodejs20-20.20.0-150500.11.24.1
* nodejs20-devel-20.20.0-150500.11.24.1
* nodejs20-debuginfo-20.20.0-150500.11.24.1
* npm20-20.20.0-150500.11.24.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch)
* nodejs20-docs-20.20.0-150500.11.24.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* nodejs20-debugsource-20.20.0-150500.11.24.1
* nodejs20-20.20.0-150500.11.24.1
* nodejs20-devel-20.20.0-150500.11.24.1
* nodejs20-debuginfo-20.20.0-150500.11.24.1
* npm20-20.20.0-150500.11.24.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
* nodejs20-docs-20.20.0-150500.11.24.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* nodejs20-debugsource-20.20.0-150500.11.24.1
* nodejs20-20.20.0-150500.11.24.1
* bsc#1256569 * bsc#1256570 * bsc#1256571 * bsc#1256573 * bsc#1256574 * bsc#1256576 * bsc#1256848 ## References: * * * * * * * * * * * * * *
*
*
*
*
*
*
*
*
*
*
*
*
*
*
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
