update for nodejs22-22.14.0-2 Update to version 22.13.1.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-e97e5c6ce3 2025-03-01 01:22:54.667691+00:00 -------------------------------------------------------------------------------- Name : nodejs22 Product : Fedora 41 Version : 22.14.0 Release : 2.fc41 URL : https://nodejs.org/en/ Summary : JavaScript runtime Description : Node.js is a platform built on Chrome's JavaScript runtime \ for easily building fast, scalable network applications. \ Node.js uses an event-driven, non-blocking I/O model that \ makes it lightweight and efficient, perfect for data-intensive \ real-time applications that run across distributed devices.} -------------------------------------------------------------------------------- Update Information: update for nodejs22-22.14.0-2 Update to version 22.13.1. -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 19 2025 Jan StanÄk - 1:22.14.0-2 - Change the default stream condition to allow for range of Fedoras - Rename the OPENSSL_NO_ENGINE guard patch to achieve the proper ordering * Tue Feb 18 2025 tjuhasz - 1:22.14.0-1 - update to version 22.14.0 (bz#2344862) * Thu Jan 23 2025 Jan StanÄk - 1:22.13.1-1 - Update to version 22.13.1 (rhbz#2330256) * Wed Jan 22 2025 Tomas Juhasz - 1:22.13.0-1 - Updated to version 22.13.0 * Fri Jan 17 2025 Fedora Release Engineering - 1:22.11.0-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2330256 - nodejs22-22.13.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2330256 [ 2 ] Bug #2341716 - CVE-2025-23083 nodejs22: Node.js Worker Thread Exposure via Diagnostics Channel [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2341716 [ 3 ] Bug #2344862 - nodejs22-22.14.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2344862 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-e97e5c6ce3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- . Upgrade nodejs22 to release 22.13.1 to address serious security flaws in Fedora 41, ensuring improved safety and performance.. Fedora Security Update, Nodejs22 Advisory, JavaScript Runtime Update. . LinuxSecurity.com Team
Worker permission bypass via InternalWorker leak in diagnostics. (CVE-2025-23083) GOAWAY HTTP/2 frames cause memory leak outside heap. (CVE-2025-23085) References: . MGASA-2025-0041 - Updated nodejs packages fix security vulnerabilities Publication date: 07 Feb 2025 URL: https://advisories.mageia.org/MGASA-2025-0041.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-23083, CVE-2025-23085 Worker permission bypass via InternalWorker leak in diagnostics. (CVE-2025-23083) GOAWAY HTTP/2 frames cause memory leak outside heap. (CVE-2025-23085) References: - https://bugs.mageia.org/show_bug.cgi?id=33947 - https://nodejs.org/en/blog/vulnerability/january-2025-security-releases - https://www.openwall.com/lists/oss-security/2025/01/21/5 - https://www.cve.org/CVERecord?id=CVE-2025-23083 - https://www.cve.org/CVERecord?id=CVE-2025-23085 SRPMS: - 9/core/nodejs-22.13.1-2.mga9 . Mageia has released updates for nodejs packages, addressing several security vulnerabilities such as memory leaks and unauthorized worker access. Read further for details.. nodejs security, mageia updates, worker bypass, memory leak fixes. . LinuxSecurity.com Team
Update to 2.1.3. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-b870a4de82 2023-09-29 00:18:30.089942 -------------------------------------------------------------------------------- Name : traceroute Product : Fedora 39 Version : 2.1.3 Release : 1.fc39 URL : Summary : Traces the route taken by packets over an IPv4/IPv6 network Description : The traceroute utility displays the route used by IP packets on their way to a specified network (or Internet) host. Traceroute displays the IP number and host name (if possible) of the machines along the route taken by the packets. Traceroute is used as a network debugging tool. If you're having network connectivity problems, traceroute will show you where the trouble is coming from along the route. Install traceroute if you need a tool for diagnosing network connectivity problems. -------------------------------------------------------------------------------- Update Information: Update to 2.1.3 -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 21 2023 Dmitry Butskoy - 3:2.1.3-1 - update to 2.1.3 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-b870a4de82' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.