Oracle Linux Security Advisory ELSA-2023-2654

https://linux.oracle.com/errata/ELSA-2023-2654.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
nodejs-18.14.2-2.module+el9.2.0+21038+115df6a2.x86_64.rpm
nodejs-devel-18.14.2-2.module+el9.2.0+21038+115df6a2.x86_64.rpm
nodejs-docs-18.14.2-2.module+el9.2.0+21038+115df6a2.noarch.rpm
nodejs-full-i18n-18.14.2-2.module+el9.2.0+21038+115df6a2.x86_64.rpm
nodejs-nodemon-2.0.20-2.module+el9.2.0+21038+115df6a2.noarch.rpm
nodejs-packaging-2021.06-4.module+el9.1.0+20762+f52d7401.noarch.rpm
nodejs-packaging-bundler-2021.06-4.module+el9.1.0+20762+f52d7401.noarch.rpm
npm-9.5.0-1.18.14.2.2.module+el9.2.0+21038+115df6a2.x86_64.rpm

aarch64:
nodejs-18.14.2-2.module+el9.2.0+21038+115df6a2.aarch64.rpm
nodejs-devel-18.14.2-2.module+el9.2.0+21038+115df6a2.aarch64.rpm
nodejs-docs-18.14.2-2.module+el9.2.0+21038+115df6a2.noarch.rpm
nodejs-full-i18n-18.14.2-2.module+el9.2.0+21038+115df6a2.aarch64.rpm
nodejs-nodemon-2.0.20-2.module+el9.2.0+21038+115df6a2.noarch.rpm
nodejs-packaging-2021.06-4.module+el9.1.0+20762+f52d7401.noarch.rpm
nodejs-packaging-bundler-2021.06-4.module+el9.1.0+20762+f52d7401.noarch.rpm
npm-9.5.0-1.18.14.2.2.module+el9.2.0+21038+115df6a2.aarch64.rpm


SRPMS:
https://oss.oracle.com:443/ol9/SRPMS-updates//nodejs-18.14.2-2.module+el9.2.0+21038+115df6a2.src.rpm
https://oss.oracle.com:443/ol9/SRPMS-updates//nodejs-nodemon-2.0.20-2.module+el9.2.0+21038+115df6a2.src.rpm
https://oss.oracle.com:443/ol9/SRPMS-updates//nodejs-packaging-2021.06-4.module+el9.1.0+20762+f52d7401.src.rpm

Related CVEs:

CVE-2021-35065
CVE-2022-4904
CVE-2022-25881
CVE-2023-23918
CVE-2023-23919
CVE-2023-23920
CVE-2023-23936
CVE-2023-24807




Description of changes:

nodejs
[1:18.14.2-2]
- Provide simduft
- Resolves: #2159389

[1:18.14.2-1]
- Rebase to 18.14.2
- Resolves: #2159389
- Resolves: CVE-2022-25881, CVE-2022-4904, CVE-2023-23936, CVE-2023-24807
- Resolves: CVE-2023-23918, CVE-2023-23919, CVE-2023-23920

nodejs-nodemon
[2.0.20-2]
- Patch bundled glob-parent
- Resolves: CVE-2021-35065

nodejs-packaging


_______________________________________________
El-errata mailing list
El-errata@oss.oracle.com
https://oss.oracle.com/mailman/listinfo/el-errata

Oracle9: ELSA-2023-2654 : 18 security, bug fix, and enhancement Moderate Security Update

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Summary

nodejs [1:18.14.2-2] - Provide simduft - Resolves: #2159389 [1:18.14.2-1] - Rebase to 18.14.2 - Resolves: #2159389 - Resolves: CVE-2022-25881, CVE-2022-4904, CVE-2023-23936, CVE-2023-24807 - Resolves: CVE-2023-23918, CVE-2023-23919, CVE-2023-23920 nodejs-nodemon [2.0.20-2] - Patch bundled glob-parent - Resolves: CVE-2021-35065 nodejs-packaging

SRPMs

https://oss.oracle.com:443/ol9/SRPMS-updates//nodejs-18.14.2-2.module+el9.2.0+21038+115df6a2.src.rpm https://oss.oracle.com:443/ol9/SRPMS-updates//nodejs-nodemon-2.0.20-2.module+el9.2.0+21038+115df6a2.src.rpm https://oss.oracle.com:443/ol9/SRPMS-updates//nodejs-packaging-2021.06-4.module+el9.1.0+20762+f52d7401.src.rpm

x86_64

nodejs-18.14.2-2.module+el9.2.0+21038+115df6a2.x86_64.rpm nodejs-devel-18.14.2-2.module+el9.2.0+21038+115df6a2.x86_64.rpm nodejs-docs-18.14.2-2.module+el9.2.0+21038+115df6a2.noarch.rpm nodejs-full-i18n-18.14.2-2.module+el9.2.0+21038+115df6a2.x86_64.rpm nodejs-nodemon-2.0.20-2.module+el9.2.0+21038+115df6a2.noarch.rpm nodejs-packaging-2021.06-4.module+el9.1.0+20762+f52d7401.noarch.rpm nodejs-packaging-bundler-2021.06-4.module+el9.1.0+20762+f52d7401.noarch.rpm npm-9.5.0-1.18.14.2.2.module+el9.2.0+21038+115df6a2.x86_64.rpm

aarch64

nodejs-18.14.2-2.module+el9.2.0+21038+115df6a2.aarch64.rpm nodejs-devel-18.14.2-2.module+el9.2.0+21038+115df6a2.aarch64.rpm nodejs-docs-18.14.2-2.module+el9.2.0+21038+115df6a2.noarch.rpm nodejs-full-i18n-18.14.2-2.module+el9.2.0+21038+115df6a2.aarch64.rpm nodejs-nodemon-2.0.20-2.module+el9.2.0+21038+115df6a2.noarch.rpm nodejs-packaging-2021.06-4.module+el9.1.0+20762+f52d7401.noarch.rpm nodejs-packaging-bundler-2021.06-4.module+el9.1.0+20762+f52d7401.noarch.rpm npm-9.5.0-1.18.14.2.2.module+el9.2.0+21038+115df6a2.aarch64.rpm

i386

Severity
Related CVEs: CVE-2021-35065 CVE-2022-4904 CVE-2022-25881 CVE-2023-23918 CVE-2023-23919 CVE-2023-23920 CVE-2023-23936 CVE-2023-24807

Related News