Alerts This Week
Warning Icon 1 1,053
Alerts This Week
Warning Icon 1 1,053

Oracle Linux 8 ELSA-2025-8514 Important: nodejs 20.19.2 Update

oracle
Calendar Grey June 13, 2025
Oracle Linux Logo Esm H88
Oracle Linux Security Update ELSA-2025-9514: Resolved critical vulnerabilities in Node.js version 20.19.3, impacting encryption standards.
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Summary

nodejs [1:20.19.2-1] - Update to version 20.19.2 Fixes: CVE-2025-23166 Resolves: RHEL-91595 RHEL-89598 RHEL-92854 [1:20.19.1-1] - Update to version 20.19.1 Resolves: RHEL-78763 [1:20.18.2-4] - Update c-ares to 1.34.5 to address CVE-2025-31498 [1:20.18.2-3] - Remove obsolete lua pretransaction script from spec file Resolves: RHEL-81125 [1:20.18.2-2] - Disable npm's update-notifier Resolves: RHEL-81077 [1:20.18.2-1] - Update to version 20.18.2 Fixes: CVE-2025-23083 CVE-2025-23085 CVE-2025-22150 Resolves: RHEL-76001 RHEL-76146 [1:20.16.0-1] - Update to 20.16.0 Fixes: CVE-2024-36137 CVE-2024-22018 CVE-2024-22020 [1:20.12.2-2] - Backport nghttp2 patch for CVE-2024-28182 [1:20.12.2-1] - Rebase to version 20.12.0 Addresses CVE-2024-27983 CVE-2024-27982 CVE-2024-22025 (node) Addresses CVE-2024-25629 (c-ares) [1:20.11.1-1] - Rebase to version 20.11.1 - Fixes: CVE-2024-21892 CVE-2024-21896 CVE-2024-22017 CVE-2024-22019 (high) - Fixes: CVE-2023-46809 CVE-2024-21...

Read the Full Advisory

SRPMs

http://oss.oracle.com/ol8/SRPMS-updates//nodejs-20.19.2-1.module+el8.10.0+90611+29f3ae1e.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//nodejs-nodemon-3.0.1-1.module+el8.10.0+90611+29f3ae1e.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//nodejs-packaging-2021.06-4.module+el8.10.0+90611+29f3ae1e.src.rpm

x86_64

nodejs-20.19.2-1.module+el8.10.0+90611+29f3ae1e.x86_64.rpm nodejs-devel-20.19.2-1.module+el8.10.0+90611+29f3ae1e.x86_64.rpm nodejs-docs-20.19.2-1.module+el8.10.0+90611+29f3ae1e.noarch.rpm nodejs-full-i18n-20.19.2-1.module+el8.10.0+90611+29f3ae1e.x86_64.rpm nodejs-nodemon-3.0.1-1.module+el8.10.0+90611+29f3ae1e.noarch.rpm nodejs-packaging-2021.06-4.module+el8.10.0+90611+29f3ae1e.noarch.rpm nodejs-packaging-bundler-2021.06-4.module+el8.10.0+90611+29f3ae1e.noarch.rpm npm-10.8.2-1.20.19.2.1.module+el8.10.0+90611+29f3ae1e.x86_64.rpm

aarch64

nodejs-20.19.2-1.module+el8.10.0+90611+29f3ae1e.aarch64.rpm nodejs-devel-20.19.2-1.module+el8.10.0+90611+29f3ae1e.aarch64.rpm nodejs-docs-20.19.2-1.module+el8.10.0+90611+29f3ae1e.noarch.rpm nodejs-full-i18n-20.19.2-1.module+el8.10.0+90611+29f3ae1e.aarch64.rpm nodejs-nodemon-3.0.1-1.module+el8.10.0+90611+29f3ae1e.noarch.rpm nodejs-packaging-2021.06-4.module+el8.10.0+90611+29f3ae1e.noarch.rpm nodejs-packaging-bundler-2021.06-4.module+el8.10.0+90611+29f3ae1e.noarch.rpm npm-10.8.2-1.20.19.2.1.module+el8.10.0+90611+29f3ae1e.aarch64.rpm

Severity
important
Lowest
Low
Medium
High
Critical

Related CVEs: CVE-2025-23166

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here