Important: nodejs:24 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:7670", "synopsis": "Important: nodejs:24 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for nodejs-nodemon, module.nodejs-packaging, module.nodejs-nodemon, nodejs-packaging.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. \n\nSecurity Fix(es):\n\n* nodejs: Nodejs denial of service (CVE-2026-21637)\n\n* minimatch: minimatch: Denial of Service via specially crafted glob patterns (CVE-2026-26996)\n\n* undici: Undici: Denial of Service due to uncontrolled resource consumption (CVE-2026-2581)\n\n* undici: Undici: HTTP header injection and request smuggling vulnerability (CVE-2026-1527)\n\n* undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression (CVE-2026-1526)\n\n* undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter (CVE-2026-2229)\n\n* undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers (CVE-2026-1525)\n\n* undici: undici: Denial of Service via crafted WebSocket frame with large length (CVE-2026-1528)\n\n* nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination (CVE-2026-27135)\n\n* Node.js: Node.js: Denial of Service via malformed Internationalized Domain Name processing (CVE-2026-21712)\n\n* Node.js: Node.js: Denial of Service due to crafted HTTP `__proto__` header (CVE-2026-21710)\n\n* Node.js: Node.js: Information disclosure due to `fs.realpathSync.native()` bypassing filesystem read restrictions (CVE-2026-21715)\n\n* nodejs: Node.js: Permission bypass allows unauthorized modification of filepermissions and ownership via incomplete security fix. (CVE-2026-21716)\n\n* Node.js: Node.js: Unauthorized inter-process communication due to missing Unix Domain Socket permission checks (CVE-2026-21711)\n\n* Node.js: Node.js: Information disclosure via timing oracle in HMAC verification (CVE-2026-21713)\n\n* Node.js: Node.js: Memory leak and Denial of Service via crafted HTTP/2 WINDOW_UPDATE frames (CVE-2026-21714)\n\n* nodejs: v8: Node.js: Denial of Service via V8 string hashing mechanism due to predictable hash collisions (CVE-2026-21717)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2431340", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431340", "description": ""}, {"ticket": "2441268", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2441268", "description": ""}, {"ticket": "2447140", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2447140", "description": ""}, {"ticket": "2447141", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2447141", "description": ""}, {"ticket": "2447142", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2447142", "description": ""}, {"ticket": "2447143", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2447143", "description": ""}, {"ticket": "2447144", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2447144", "description": ""}, {"ticket": "2447145", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2447145", "description": ""}, {"ticket": "2448754", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2448754", "description": ""}, {"ticket": "2453037","sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2453037", "description": ""}, {"ticket": "2453151", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2453151", "description": ""}, {"ticket": "2453152", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2453152", "description": ""}, {"ticket": "2453157", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2453157", "description": ""}, {"ticket": "2453158", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2453158", "description": ""}, {"ticket": "2453160", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2453160", "description": ""}, {"ticket": "2453161", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2453161", "description": ""}, {"ticket": "2453162", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2453162", "description": ""}], "cves": [{"name": "CVE-2026-1525", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1525", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", "cvss3BaseScore": "7.3", "cwe": "CWE-444"}, {"name": "CVE-2026-1526", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1526", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-770"}, {"name": "CVE-2026-1527", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1527", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L", "cvss3BaseScore": "6.5", "cwe": "CWE-93"}, {"name": "CVE-2026-1528", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1528", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-248"}, {"name": "CVE-2026-21637","sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21637", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.9", "cwe": "CWE-248"}, {"name": "CVE-2026-21710", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21710", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-843"}, {"name": "CVE-2026-21711", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21711", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N", "cvss3BaseScore": "5.2", "cwe": "CWE-940"}, {"name": "CVE-2026-21712", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21712", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "cvss3BaseScore": "6.5", "cwe": "CWE-168"}, {"name": "CVE-2026-21713", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21713", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "cvss3BaseScore": "5.9", "cwe": "CWE-208"}, {"name": "CVE-2026-21714", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21714", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "cvss3BaseScore": "5.3", "cwe": "CWE-772"}, {"name": "CVE-2026-21715", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21715", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N", "cvss3BaseScore": "3.3", "cwe": "CWE-425"}, {"name": "CVE-2026-21716", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21716", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N", "cvss3BaseScore": "3.8", "cwe": "CWE-279"}, {"name": "CVE-2026-21717", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-21717","cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.9", "cwe": "CWE-328"}, {"name": "CVE-2026-2229", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2229", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-248"}, {"name": "CVE-2026-2581", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2581", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.9", "cwe": "CWE-770"}, {"name": "CVE-2026-26996", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-26996", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "cvss3BaseScore": "6.5", "cwe": "CWE-1333"}, {"name": "CVE-2026-27135", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27135", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-617"}], "references": [], "publishedAt": "2026-04-13T06:01:13.567166Z", "rpms": {"Rocky Linux 8": {"nvras": ["nodejs-nodemon-0:3.0.3-1.module+el8.10.0+2084+ab509703.noarch.rpm", "nodejs-nodemon-0:3.0.3-1.module+el8.10.0+2084+ab509703.src.rpm", "nodejs-packaging-0:2021.06-6.module+el8.10.0+40048+6d99f608.noarch.rpm", "nodejs-packaging-0:2021.06-6.module+el8.10.0+40048+6d99f608.src.rpm", "nodejs-packaging-bundler-0:2021.06-6.module+el8.10.0+40048+6d99f608.noarch.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important nodejs updates available for Rocky Linux 8 addressing multiple security issues including Denial of Service attacks.. Rocky Linux nodejs security update Denial of Service CVE. . Severity: Important. LinuxSecurity.com Team
An integer overflow in Poco::UTF32Encoding() hase been fixed in the POCO C++ libraries for building network-based applications. For Debian 11 bullseye, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4024-1
nodejs:22 bug fix and enhancement update. {"type":"TYPE_ENHANCEMENT","shortCode":"RL","name":"RLEA-2024:11235","synopsis":"nodejs:22 bug fix and enhancement update","severity":"SEVERITY_UNKNOWN","topic":"An update is available for nodejs-nodemon, module.nodejs-nodemon, module.nodejs-packaging, nodejs-packaging.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list","description":"Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. \n\nBug Fix(es) and Enhancement(s):\n\n* [Rocky Linux-9] nodejs:22\/nodejs: Rebase Node.js 22 to LTS version [rhel-9.5.z] (JIRA:Rocky Linux-67327)","solution":null,"affectedProducts":["Rocky Linux 9"],"fixes":[],"cves":[],"references":[],"publishedAt":"2024-12-19T04:19:20.875733Z","rpms":{"Rocky Linux 9":{"nvras":["nodejs-nodemon-0:3.0.1-1.module+el9.4.0+25495+f51dca35.noarch.rpm","nodejs-nodemon-0:3.0.1-1.module+el9.4.0+25495+f51dca35.src.rpm","nodejs-packaging-0:2021.06-4.module+el9.4.0+25495+f51dca35.noarch.rpm","nodejs-packaging-0:2021.06-4.module+el9.4.0+25495+f51dca35.src.rpm","nodejs-packaging-bundler-0:2021.06-4.module+el9.4.0+25495+f51dca35.noarch.rpm"]}},"rebootSuggested":false,"buildReferences":[]}. Node.js repair and optimization patch for Rocky Linux 9, focusing on critical software upgrades and enhancements.. Rocky Linux, Node.js update, bug fix, software enhancements. . LinuxSecurity.com Team
## 2022-02-08, Version 16.14.0 'Gallium' (LTS), @danielleadams ### Notable changes #### Importing JSON modules now requires experimental import assertions syntax This release adds experimental support for the import assertions stage 3 proposal. To keep Node.js ESM implementation as compatible as possible with the HTML spec, import assertions are now required to import JSON modules (still. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-97b214b298 2022-02-19 01:30:44.345535 --------------------------------------------------------------------------------Name : nodejs Product : Fedora 35 Version : 16.14.0 Release : 2.fc35 URL : https://nodejs.org/en/ Summary : JavaScript runtime Description : Node.js is a platform built on Chrome's JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices. --------------------------------------------------------------------------------Update Information: ## 2022-02-08, Version 16.14.0 'Gallium' (LTS), @danielleadams ### Notable changes #### Importing JSON modules now requires experimental import assertions syntax This release adds experimental support for the import assertions stage 3 proposal. To keep Node.js ESM implementation as compatible as possible with the HTML spec, import assertions are now required to import JSON modules (still behind the `--experimental-json-modules` CLI flag): ```mjs import info from './package.json' assert { type: 'json' }; ``` Or use dynamic import: ```mjs const info = await import('./package.json', { assert: { type: 'json' } }); ``` Contributed by Antoine du Hamel and Geoffrey Booth [#40250](https://github.com/nodejs/node/pull/40250) #### Other notable changes * **async\_hooks**: * **(SEMVER-MINOR)** exposeasync\_wrap providers (Rafael Gonzaga) [#40760](https://github.com/nodejs/node/pull/40760) * **child\_process**: * **(SEMVER-MINOR)** add support for URL to `cp.fork` (Antoine du Hamel) [#41225](https://github.com/nodejs/node/pull/41225) * **doc**: * add @Mesteery to collaborators (Mestery) [#41543](https://github.com/nodejs/node/pull/41543) * add @bnb as a collaborator (Tierney Cyren) [#41100](https://github.com/nodejs/node/pull/41100) * **esm**: * **(SEMVER-MINOR)** graduate capturerejections to supported (James M Snell) [#41267](https://github.com/nodejs/node/pull/41267) * **(SEMVER-MINOR)** add EventEmitterAsyncResource to core (James M Snell) [#41246](https://github.com/nodejs/node/pull/41246) * **events**: * **(SEMVER-MINOR)** propagate weak option for kNewListener (James M Snell) [#40899](https://github.com/nodejs/node/pull/40899) * **fs**: * **(SEMVER-MINOR)** accept URL as argument for `fs.rm` and `fs.rmSync` (Antoine du Hamel) [#41132](https://github.com/nodejs/node/pull/41132) * **lib**: * **(SEMVER-MINOR)** make AbortSignal cloneable/transferable (James M Snell) [#41050](https://github.com/nodejs/node/pull/41050) * **(SEMVER-MINOR)** add AbortSignal.timeout (James M Snell) [#40899](https://github.com/nodejs/node/pull/40899) * **(SEMVER-MINOR)** add reason to AbortSignal (James M Snell) [#40807](https://github.com/nodejs/node/pull/40807) * **(SEMVER-MINOR)** add unsubscribe method to non-active DC channels (simon-id) [#40433](https://github.com/nodejs/node/pull/40433) * **(SEMVER-MINOR)** add return value for DC channel.unsubscribe (simon-id) [#40433](https://github.com/nodejs/node/pull/40433) * **loader**: * **(SEMVER-MINOR)** return package format from defaultResolve if known (Gabriel Bota) [#40980](https://github.com/nodejs/node/pull/40980) * **perf\_hooks**: * **(SEMVER-MINOR)** multiple fixes for Histogram (James M Snell) [#41153](https://github.com/nodejs/node/pull/41153) * **process**: * **(SEMVER-MINOR)** add `getActiveResourcesInfo()`(Darshan Sen) [#40813](https://github.com/nodejs/node/pull/40813) * **src**: * **(SEMVER-MINOR)** add x509.fingerprint512 to crypto module (3nprob) [#39809](https://github.com/nodejs/node/pull/39809) * **(SEMVER-MINOR)** add flags for controlling process behavior (Cheng Zhao) [#40339](https://github.com/nodejs/node/pull/40339) * **stream**: * **(SEMVER-MINOR)** add filter method to readable (Benjamin Gruenbaum) [#41354](https://github.com/nodejs/node/pull/41354) * **(SEMVER-MINOR)** add isReadable helper (Robert Nagy) [#41199](https://github.com/nodejs/node/pull/41199) * **(SEMVER-MINOR)** add map method to Readable (Benjamin Gruenbaum) [#40815](https://github.com/nodejs/node/pull/40815) * deprecate thenable support (Antoine du Hamel) [#40860](https://github.com/nodejs/node/pull/40860) * **util**: * **(SEMVER-MINOR)** pass through the inspect function to custom inspect functions (Ruben Bridgewater) [#41019](https://github.com/nodejs/node/pull/41019) * **(SEMVER-MINOR)** add numericSeparator to util.inspect (Ruben Bridgewater) [#41003](https://github.com/nodejs/node/pull/41003) * **(SEMVER-MINOR)** always visualize cause property in errors during inspection (Ruben Bridgewater) [#41002](https://github.com/nodejs/node/pull/41002) * **timers**: * **(SEMVER-MINOR)** add experimental scheduler api (James M Snell) [#40909](https://github.com/nodejs/node/pull/40909) * **v8**: * **(SEMVER-MINOR)** multi-tenant promise hook api (Stephen Belanger) [#39283](https://github.com/nodejs/node/pull/39283) ---- Fix for CVE-2021-43616 --------------------------------------------------------------------------------ChangeLog: * Wed Feb 9 2022 Zuzana Svetlikova - 1:16.14.0-2 - Replace explicit version of npm in %check with variable and make build fail if it doesn't match * Tue Feb 8 2022 Stephen Gallagher - 1:16.14.0-1 - Update to Node.js 16.14.0 * Thu Feb 3 2022 Stephen Gallagher - 1:16.13.2-8 - Update npm to 8.3.1 (CVE-2021-43616) * Wed Feb 2 2022 Stephen Gallagher -1:16.13.2-7 - Fix incorrect version Provides: for npm (bz#2049873) * Mon Jan 31 2022 Stephen Gallagher - 1:16.13.2-6 - Rebuild for more architectures * Mon Jan 31 2022 Stephen Gallagher - 1:16.13.2-5 - Tweak some dependencies on EPEL 7 (bz2048589) - Add Provides: bundled(zlib) * Wed Jan 19 2022 Stephen Gallagher - 1:16.13.2-3 - Bundle zlib on EPEL 7 * Mon Jan 17 2022 Stephen Gallagher - 1:16.13.2-2 - Add support for building on EPEL 7 --------------------------------------------------------------------------------References: [ 1 ] Bug #2050282 - CVE-2021-43616 npm: npm ci succeeds when package-lock.json doesn't match package.json https://bugzilla.redhat.com/show_bug.cgi?id=2050282 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-97b214b298' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update for rh-nodejs14-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-nodejs14-nodejs security update Advisory ID: RHSA-2021:0421-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2021:0421 Issue date: 2021-02-04 CVE Names: CVE-2020-7754 CVE-2020-7774 CVE-2020-7788 CVE-2020-8265 CVE-2020-8277 CVE-2020-8287 CVE-2020-15366 ==================================================================== 1. Summary: An update for rh-nodejs14-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64 3. Description: Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. The following packages have been upgraded to a later upstream version: rh-nodejs14-nodejs (14.15.4). Security Fix(es): * nodejs-npm-user-validate: improper input validation when validatinguser emails leads to ReDoS (CVE-2020-7754) * nodejs-y18n: prototype pollution vulnerability (CVE-2020-7774) * nodejs-ini: prototype pollution via malicious INI file (CVE-2020-7788) * nodejs: use-after-free in the TLS implementation (CVE-2020-8265) * c-ares: ares_parse_{a,aaaa}_reply() insufficient naddrttls validation DoS (CVE-2020-8277) * nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function (CVE-2020-15366) * nodejs: HTTP request smuggling via two copies of a header field in an http request (CVE-2020-8287) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1857977 - CVE-2020-15366 nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function 1892430 - CVE-2020-7754 nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS 1898554 - CVE-2020-8277 c-ares: ares_parse_{a,aaaa}_reply() insufficient naddrttls validation DoS 1898680 - CVE-2020-7774 nodejs-y18n: prototype pollution vulnerability 1907444 - CVE-2020-7788 nodejs-ini: prototype pollution via malicious INI file 1912854 - CVE-2020-8265 nodejs: use-after-free in the TLS implementation 1912863 - CVE-2020-8287 nodejs: HTTP request smuggling via two copies of a header field in an http request 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server (v.7): Source: rh-nodejs14-nodejs-14.15.4-2.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.15.4-2.el7.noarch.rpm ppc64le: rh-nodejs14-nodejs-14.15.4-2.el7.ppc64le.rpm rh-nodejs14-nodejs-debuginfo-14.15.4-2.el7.ppc64le.rpm rh-nodejs14-nodejs-devel-14.15.4-2.el7.ppc64le.rpm rh-nodejs14-npm-6.14.10-14.15.4.2.el7.ppc64le.rpm s390x: rh-nodejs14-nodejs-14.15.4-2.el7.s390x.rpm rh-nodejs14-nodejs-debuginfo-14.15.4-2.el7.s390x.rpm rh-nodejs14-nodejs-devel-14.15.4-2.el7.s390x.rpm rh-nodejs14-npm-6.14.10-14.15.4.2.el7.s390x.rpm x86_64: rh-nodejs14-nodejs-14.15.4-2.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.15.4-2.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.15.4-2.el7.x86_64.rpm rh-nodejs14-npm-6.14.10-14.15.4.2.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6): Source: rh-nodejs14-nodejs-14.15.4-2.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.15.4-2.el7.noarch.rpm ppc64le: rh-nodejs14-nodejs-14.15.4-2.el7.ppc64le.rpm rh-nodejs14-nodejs-debuginfo-14.15.4-2.el7.ppc64le.rpm rh-nodejs14-nodejs-devel-14.15.4-2.el7.ppc64le.rpm rh-nodejs14-npm-6.14.10-14.15.4.2.el7.ppc64le.rpm s390x: rh-nodejs14-nodejs-14.15.4-2.el7.s390x.rpm rh-nodejs14-nodejs-debuginfo-14.15.4-2.el7.s390x.rpm rh-nodejs14-nodejs-devel-14.15.4-2.el7.s390x.rpm rh-nodejs14-npm-6.14.10-14.15.4.2.el7.s390x.rpm x86_64: rh-nodejs14-nodejs-14.15.4-2.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.15.4-2.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.15.4-2.el7.x86_64.rpm rh-nodejs14-npm-6.14.10-14.15.4.2.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v.7.7): Source: rh-nodejs14-nodejs-14.15.4-2.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.15.4-2.el7.noarch.rpm ppc64le: rh-nodejs14-nodejs-14.15.4-2.el7.ppc64le.rpm rh-nodejs14-nodejs-debuginfo-14.15.4-2.el7.ppc64le.rpm rh-nodejs14-nodejs-devel-14.15.4-2.el7.ppc64le.rpm rh-nodejs14-npm-6.14.10-14.15.4.2.el7.ppc64le.rpm s390x: rh-nodejs14-nodejs-14.15.4-2.el7.s390x.rpm rh-nodejs14-nodejs-debuginfo-14.15.4-2.el7.s390x.rpm rh-nodejs14-nodejs-devel-14.15.4-2.el7.s390x.rpm rh-nodejs14-npm-6.14.10-14.15.4.2.el7.s390x.rpm x86_64: rh-nodejs14-nodejs-14.15.4-2.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.15.4-2.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.15.4-2.el7.x86_64.rpm rh-nodejs14-npm-6.14.10-14.15.4.2.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7): Source: rh-nodejs14-nodejs-14.15.4-2.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.15.4-2.el7.noarch.rpm x86_64: rh-nodejs14-nodejs-14.15.4-2.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.15.4-2.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.15.4-2.el7.x86_64.rpm rh-nodejs14-npm-6.14.10-14.15.4.2.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-7754 https://access.redhat.com/security/cve/CVE-2020-7774 https://access.redhat.com/security/cve/CVE-2020-7788 https://access.redhat.com/security/cve/CVE-2020-8265 https://access.redhat.com/security/cve/CVE-2020-8277 https://access.redhat.com/security/cve/CVE-2020-8287 https://access.redhat.com/security/cve/CVE-2020-15366 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYBwsltzjgjWX9erEAQjfrQ/8CZ3Sx8P+gFao3TvTIb1H1kKU1AqncYGw JdrVsDhjVxVixQ6voH4vK3BTaO0/lcoDf1gV2Ot+QduIOzbsnFVXtcATg1Ada5+W 5VDgT206n7NtUdpO8k79wz41S7DLQq48EHCvCZpyDg7CKkwVEDMPXOsXEuJUHkeL 6VXkvMeVe5vulxrUm7u/uovFBg4oEzAkUxpwdDJV3e8TiyUJDAbPjfHsudnAp5LS cGGu5HlKCWQKg/NPmY0n6R2f5ZJbCUXMWz+klgqG78jsnqvT0pxT7yfhoQtKx+hE qua/PRASNqr6TGxvTGVUcbcMecWPaBKLnvFBPZhMKYcqc0Tu/IOzCg/j2VI03cB0 D4nix+S+ZAHSjcje0g8SayW6CNd+D21/yn3viR1JvG1v+ptgLBEqeYm4UH1TJAKg h/rGaB1ErOuaiVjhP2UC+g7A1JRA6UFMMXCTHi/8vMTRHFDEdjNrn6IIV/R+f+1Q SXWojgWAoylt8ZoSLZSv0tcW92iT4l6pyr6x5GYpoDg6t8VU24HFUUcmm8home/g h3wTHfEGuKvPfLyvGZjP0cQAlw9+PaHxM6fzOgtwZmWJ0iomLDKoJROJ6RcJJIql CDPcVzxup5Vu7EBYPFG6GtaFTQu6BwsoUVI8Ownq6xBONuu651VyT92T+6YJfbj9 i0lfIZ/DfUY=9Rxl -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-711 2006-06-19 ---------------------------------------------------------------------Product : Fedora Core 5 Name : kdenetwork Version : 3.5.3 Release : 0.1.fc5 Summary : K Desktop Environment - Network Applications Description : Networking applications for the K Desktop Environment. ---------------------------------------------------------------------Update Information: KDE 3.5.3 release Qt 3.3.6 release ---------------------------------------------------------------------* Fri Jun 9 2006 Than Ngo 7:3.5.3-0.1.fc5 - update to 3.5.3 * Sun May 7 2006 Than Ngo 7:3.5.2-0.2.fc5 - fix #189691, kopete crash after selecting Setting-> Configure-> device ---------------------------------------------------------------------This update can be downloaded from: 840bd536ac842b59570790c5b151b94a4a6d43fe SRPMS/kdenetwork-3.5.3-0.1.fc5.src.rpm 840bd536ac842b59570790c5b151b94a4a6d43fe noarch/kdenetwork-3.5.3-0.1.fc5.src.rpm da1be65a04405434482681a1b530d84a8014202c ppc/kdenetwork-3.5.3-0.1.fc5.ppc.rpm 7c33171d986052618ca8612e0841e259d4825f0d ppc/debug/kdenetwork-debuginfo-3.5.3-0.1.fc5.ppc.rpm 91116e51e39564e5ea7e3d6eabbd531fa32aa649 ppc/kdenetwork-devel-3.5.3-0.1.fc5.ppc.rpm 97f0b4645fc6d078234409925c4b7688b3765930 x86_64/kdenetwork-devel-3.5.3-0.1.fc5.x86_64.rpm c0450501123eb0ccee89a47331a0622b794e1f67 x86_64/debug/kdenetwork-debuginfo-3.5.3-0.1.fc5.x86_64.rpm dc6e6529de2acb36877c1735aee2375d73862ac6 x86_64/kdenetwork-3.5.3-0.1.fc5.x86_64.rpm 557b42556b0ab9ab4d69d1f8541c6f005a17d185 i386/kdenetwork-3.5.3-0.1.fc5.i386.rpm a0a348c5a8f4c42dbc7cb34514b5d7407801cd60 i386/kdenetwork-devel-3.5.3-0.1.fc5.i386.rpm 2a8c1b385a0e4395debadcd034c4fd656759222b i386/debug/kdenetwork-debuginfo-3.5.3-0.1.fc5.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at thecommand line. For more information, refer to 'Managing Software with yum,' available at . ---------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list
update to KDE 3.5.2. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-381 2006-04-18 ---------------------------------------------------------------------Product : Fedora Core 4 Name : kdenetwork Version : 3.5.2 Release : 0.1.fc4 Summary : K Desktop Environment - Network Applications Description : Networking applications for the K Desktop Environment. ---------------------------------------------------------------------Update Information: update to KDE 3.5.2 ---------------------------------------------------------------------* Wed Apr 12 2006 Than Ngo 7:3.5.2-0.1.fc4 - update to 3.5.2 ---------------------------------------------------------------------This update can be downloaded from: 3d33fda5f47229e3874f821bd995136e2da4bf24 SRPMS/kdenetwork-3.5.2-0.1.fc4.src.rpm 3ef6221c050639336e7cd78b7b4f2a0ee8e19923 ppc/kdenetwork-3.5.2-0.1.fc4.ppc.rpm c48ddf97b4f346c5276b1277fd65ffda3c4acfb7 ppc/kdenetwork-devel-3.5.2-0.1.fc4.ppc.rpm d894a973b3f87890252d8c7cfc84b023fc6b8606 ppc/debug/kdenetwork-debuginfo-3.5.2-0.1.fc4.ppc.rpm 470129e2d5e47d23042d66fa10524c14a8e4d557 x86_64/kdenetwork-3.5.2-0.1.fc4.x86_64.rpm d829e0b11fefbab941e945a922eb3cd8f3027079 x86_64/kdenetwork-devel-3.5.2-0.1.fc4.x86_64.rpm 529f1f13d5a62785adc82bb5dba0c28b3efa93bf x86_64/debug/kdenetwork-debuginfo-3.5.2-0.1.fc4.x86_64.rpm 742c99212297d0ec291188c57a9138fc386f2e2a i386/kdenetwork-3.5.2-0.1.fc4.i386.rpm ba7e9d8a4ae799d67ddc85c8679979b053583d38 i386/kdenetwork-devel-3.5.2-0.1.fc4.i386.rpm 3fed1098a921e30182ce4982fed911356dfbf9eb i386/debug/kdenetwork-debuginfo-3.5.2-0.1.fc4.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailinglist
update to KDE 3.4.2. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-711 2005-08-15 ---------------------------------------------------------------------Product : Fedora Core 3 Name : kdenetwork Version : 3.4.2 Release : 0.fc3.1 Summary : K Desktop Environment - Network Applications Description : Networking applications for the K Desktop Environment. ---------------------------------------------------------------------Update Information: update to KDE 3.4.2 ---------------------------------------------------------------------* Fri Aug 5 2005 Than Ngo 7:3.4.2-0.fc3.1 - update to 3.4.2 ---------------------------------------------------------------------This update can be downloaded from: 4f0ae0a85fe8229c690414b1de9c06d2 SRPMS/kdenetwork-3.4.2-0.fc3.1.src.rpm d73e8e1760256971bc483aafaf4ff24e x86_64/kdenetwork-3.4.2-0.fc3.1.x86_64.rpm d90de2302bd26d91141962b7c262e88f x86_64/kdenetwork-devel-3.4.2-0.fc3.1.x86_64.rpm a4f11b420d396a2b72ec646eddbf476b x86_64/kdenetwork-nowlistening-3.4.2-0.fc3.1.x86_64.rpm 023535189ed85593f719b1c526b87a8b x86_64/debug/kdenetwork-debuginfo-3.4.2-0.fc3.1.x86_64.rpm c34ff4b60030bd553cad7d14c1fb93ad i386/kdenetwork-3.4.2-0.fc3.1.i386.rpm 48df79dff58d9588aab5ddc54a493fd2 i386/kdenetwork-devel-3.4.2-0.fc3.1.i386.rpm 85c70029cbfe132ce893bbd36882daa0 i386/kdenetwork-nowlistening-3.4.2-0.fc3.1.i386.rpm 372a7a34ac322fcbbd304d03b6e53b28 i386/debug/kdenetwork-debuginfo-3.4.2-0.fc3.1.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.