Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-4461 http://linux.oracle.com/errata/ELSA-2025-4461.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: nodejs-20.19.1-1.module+el8.10.0+90560+49d7a1eb.x86_64.rpm nodejs-devel-20.19.1-1.module+el8.10.0+90560+49d7a1eb.x86_64.rpm nodejs-docs-20.19.1-1.module+el8.10.0+90560+49d7a1eb.noarch.rpm nodejs-full-i18n-20.19.1-1.module+el8.10.0+90560+49d7a1eb.x86_64.rpm nodejs-nodemon-3.0.1-1.module+el8.10.0+90560+49d7a1eb.noarch.rpm nodejs-packaging-2021.06-4.module+el8.10.0+90560+49d7a1eb.noarch.rpm nodejs-packaging-bundler-2021.06-4.module+el8.10.0+90560+49d7a1eb.noarch.rpm npm-10.8.2-1.20.19.1.1.module+el8.10.0+90560+49d7a1eb.x86_64.rpm aarch64: nodejs-20.19.1-1.module+el8.10.0+90560+49d7a1eb.aarch64.rpm nodejs-devel-20.19.1-1.module+el8.10.0+90560+49d7a1eb.aarch64.rpm nodejs-docs-20.19.1-1.module+el8.10.0+90560+49d7a1eb.noarch.rpm nodejs-full-i18n-20.19.1-1.module+el8.10.0+90560+49d7a1eb.aarch64.rpm nodejs-nodemon-3.0.1-1.module+el8.10.0+90560+49d7a1eb.noarch.rpm nodejs-packaging-2021.06-4.module+el8.10.0+90560+49d7a1eb.noarch.rpm nodejs-packaging-bundler-2021.06-4.module+el8.10.0+90560+49d7a1eb.noarch.rpm npm-10.8.2-1.20.19.1.1.module+el8.10.0+90560+49d7a1eb.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//nodejs-20.19.1-1.module+el8.10.0+90560+49d7a1eb.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//nodejs-nodemon-3.0.1-1.module+el8.10.0+90560+49d7a1eb.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//nodejs-packaging-2021.06-4.module+el8.10.0+90560+49d7a1eb.src.rpm Related CVEs: CVE-2025-31498 Description of changes: nodejs [1:20.19.1-1] - Update to version 20.19.1 Resolves: RHEL-78763 [1:20.18.2-4] - Update c-ares to 1.34.5 to address CVE-2025-31498 _______________________________________________ El-errata mailinglist
An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for nodejs10 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:0063-1 Rating: important References: #1149792 #1159352 #1159812 Cross-References: CVE-2019-16775 CVE-2019-16776 CVE-2019-16777 Affected Products: SUSE Linux Enterprise Module for Web Scripting 12 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for nodejs10 to version 10.18.0 fixes the following issues: Security issues fixed: - CVE-2019-16777, CVE-2019-16776, CVE-2019-16775: Updated npm to 6.13.4, fixing an arbitrary path overwrite and access via "bin" field (bsc#1159352). - Added support for chacha20-poly1305 for Authenticated encryption (AEAD). Non-security issues fixed: - Fix wrong path in gypi files (bsc#1159812) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2020-63=1 Package List: - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): nodejs10-10.18.0-1.15.1 nodejs10-debuginfo-10.18.0-1.15.1 nodejs10-debugsource-10.18.0-1.15.1 nodejs10-devel-10.18.0-1.15.1 npm10-10.18.0-1.15.1 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): nodejs10-docs-10.18.0-1.15.1 References: https://www.suse.com/security/cve/CVE-2019-16775.html https://www.suse.com/security/cve/CVE-2019-16776.html https://www.suse.com/security/cve/CVE-2019-16777.html https://bugzilla.suse.com/1149792 https://bugzilla.suse.com/1159352 https://bugzilla.suse.com/1159812 _______________________________________________ sle-security-updates mailing list
An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for nodejs8 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:0043-1 Rating: important References: #1149792 #1159352 Cross-References: CVE-2019-16775 CVE-2019-16776 CVE-2019-16777 Affected Products: SUSE Linux Enterprise Module for Web Scripting 15-SP1 SUSE Linux Enterprise Module for Web Scripting 15 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for nodejs8 to version 8.17.0 fixes the following issues: Security issues fixed: - CVE-2019-16777, CVE-2019-16776, CVE-2019-16775: Updated npm to 6.13.4, fixing an arbitrary path overwrite and access via "bin" field (bsc#1159352). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Web Scripting 15-SP1: zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP1-2020-43=1 - SUSE Linux Enterprise Module for Web Scripting 15: zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-2020-43=1 Package List: - SUSE Linux Enterprise Module for Web Scripting 15-SP1 (aarch64 ppc64le s390x x86_64): nodejs8-8.17.0-3.25.1 nodejs8-debuginfo-8.17.0-3.25.1 nodejs8-debugsource-8.17.0-3.25.1 nodejs8-devel-8.17.0-3.25.1 npm8-8.17.0-3.25.1 - SUSE Linux Enterprise Module for Web Scripting 15-SP1 (noarch): nodejs8-docs-8.17.0-3.25.1 - SUSE Linux Enterprise Module for Web Scripting 15 (aarch64 ppc64le s390x x86_64): nodejs8-8.17.0-3.25.1 nodejs8-debuginfo-8.17.0-3.25.1 nodejs8-debugsource-8.17.0-3.25.1 nodejs8-devel-8.17.0-3.25.1 npm8-8.17.0-3.25.1 - SUSE Linux Enterprise Module for Web Scripting 15 (noarch): nodejs8-docs-8.17.0-3.25.1 References: https://www.suse.com/security/cve/CVE-2019-16775.html https://www.suse.com/security/cve/CVE-2019-16776.html https://www.suse.com/security/cve/CVE-2019-16777.html https://bugzilla.suse.com/1149792 https://bugzilla.suse.com/1159352 _______________________________________________ sle-security-updates mailing list
Get the latest Linux and open source security news straight to your inbox.