Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Mageia 9: 2025-0161 critical: nodejs process crash and improper handling

mageia
Calendar Grey May 24, 2025
Dist Mageia Esm H88
Mageia 2025-0162 addresses critical Python security flaws, including memory leaks and unsafe input validation. Discover further details here
Corrupted pointer in node::fs::ReadFileUtf8(const FunctionCallbackInfo& args) when args[0] is a string

Summary

Corrupted pointer in node::fs::ReadFileUtf8(const FunctionCallbackInfo& args) when args[0] is a string. (CVE-2025-23165) Improper error handling in async cryptographic operations crashes process. (CVE-2025-23166) Improper HTTP header block termination in llhttp. (CVE-2025-23167)

References

- https://bugs.mageia.org/show_bug.cgi?id=34278

- https://nodejs.org/en/blog/vulnerability/may-2025-security-releases

- https://www.cve.org/CVERecord?id=CVE-2025-23165

- https://www.cve.org/CVERecord?id=CVE-2025-23166

- https://www.cve.org/CVERecord?id=CVE-2025-23167

Resolution

SRPMS

- 9/core/nodejs-22.16.0-1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 24 May 2025
URL: https://advisories.mageia.org/MGASA-2025-0161.html
Type: security
CVE: CVE-2025-23165, CVE-2025-23166, CVE-2025-23167

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here