Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 42: nodejs20 2025-2936dece0e critical: Memory Leak Leading to DoS

fedora
Calendar Grey May 28, 2025
Dist Fedora Esm H88
Fedora announces a crucial security update for python39, moving to version 3.9.17 that addresses significant vulnerabilities. Take steps to secure your system today!
Update to 20.19.2

Summary

Node.js is a platform built on Chrome's JavaScript runtime \

for easily building fast, scalable network applications. \

Node.js uses an event-driven, non-blocking I/O model that \

makes it lightweight and efficient, perfect for data-intensive \

real-time applications that run across distributed devices.}

Update Information:

Update to 20.19.2

Change Log

* Thu May 15 2025 tjuhasz - 1:20.19.2-1 - Update to version 20.19.2 (rhbz#2366363) * Fri May 2 2025 tjuhasz - 1:20.19.1-2 - Changed library link from nodejs to node (rhbz#2275382)

References


[ 1 ] Bug #2294838 - nodejs-devel pkgconfig file is invalid https://bugzilla.redhat.com/show_bug.cgi?id=2294838 [ 2 ] Bug #2367229 - CVE-2025-23165 nodejs20: Memory Leak in Node.js ReadFileUtf8 Binding Leading to DoS [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2367229 [ 3 ] Bug #2367231 - CVE-2025-23165 nodejs20: Memory Leak in Node.js ReadFileUtf8 Binding Leading to DoS [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2367231 [ 4 ] Bug #2367233 - CVE-2025-23167 nodejs20: Improper HTTP Header Termination in Node.js 20 Enables Request Smuggling [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2367233 [ 5 ] Bug #2367234 - CVE-2025-23167 nodejs20: Improper HTTP Header Termination in Node.js 20 Enables Request Smuggling [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2367234 [ 6 ] Bug #2367236 - CVE-2025-23166 nodejs20: Remote Crash via SignTraits::DeriveBits() in Node.js [fedora-41] ...

Read the Full Advisory

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-2936dece0e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: nodejs20
Product: Fedora 42
Version: 20.19.2
Release: 1.fc42
Summary: JavaScript runtime

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here