Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

openSUSE Leap 16.0 Nodejs22 Important Denial of Service Fix 2026-20236-1

opensuse
Calendar Grey February 17, 2026
Dist Opensuse Esm H88
An important update for openSUSE fixed 7 vulnerabilities in nodejs22. Ensure your systems are patched for better security.
An update that solves 7 vulnerabilities and has 7 bug fixes can now be installed.

Description

This update for nodejs22 fixes the following issues:

Update to 22.22.0:

- CVE-2025-55130: file system permissions bypass via crafted symlinks (bsc#1256569).

- CVE-2025-55131: timeout-based race conditions allow for allocations that contain leftover data from previous operations and lead to exposure of in-process secrets (bsc#1256570).

- CVE-2025-55132: a file's access and modification timestamps can be changed via `futimes()` even when the process has only read permissions (bsc#1256571).

- CVE-2025-59465: malformed HTTP/2 HEADERS frame with invalid HPACK data can cause a crash due to an unhandled error (bsc#1256573).

- CVE-2025-59466: uncatchable "Maximum call stack size exceeded" error when `async_hooks.createHook()` is enabled can lead to crash (bsc#1256574).

- CVE-2026-21637: synchronous exceptions thrown during certain callbacks bypass the standard TLS error handling paths and can cause a denial of service (bsc#1256576).

- CVE-2026-22036: undici: unbounded decompression chain...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

corepack22-22.22.0-160000.1.1

nodejs22-22.22.0-160000.1.1

nodejs22-devel-22.22.0-160000.1.1

nodejs22-docs-22.22.0-160000.1.1

npm22-22.22.0-160000.1.1

References

* bsc#1256569

* bsc#1256570

* bsc#1256571

* bsc#1256573

* bsc#1256574

* bsc#1256576

* bsc#1256848

References:

* https://www.suse.com/security/cve/CVE-2025-55130.html

* https://www.suse.com/security/cve/CVE-2025-55131.html

* https://www.suse.com/security/cve/CVE-2025-55132.html

* https://www.suse.com/security/cve/CVE-2025-59465.html

* https://www.suse.com/security/cve/CVE-2025-59466.html

* https://www.suse.com/security/cve/CVE-2026-21637.html

* https://www.suse.com/security/cve/CVE-2026-22036.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:20236-1
Rating: important
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here