Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Important: nodejs:22 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:2782", "synopsis": "Important: nodejs:22 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for nodejs-packaging, module.nodejs-nodemon, module.nodejs-packaging, nodejs-nodemon.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. \n\nSecurity Fix(es):\n\n* nodejs: Nodejs filesystem permissions bypass (CVE-2025-55132)\n\n* nodejs: Nodejs denial of service (CVE-2026-21637)\n\n* nodejs: Nodejs denial of service (CVE-2025-59466)\n\n* nodejs: Nodejs denial of service (CVE-2025-59465)\n\n* nodejs: Nodejs uninitialized memory exposure (CVE-2025-55131)\n\n* nodejs: Nodejs file permissions bypass (CVE-2025-55130)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2431338", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431338", "description": ""}, {"ticket": "2431340", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431340", "description": ""}, {"ticket": "2431343", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431343", "description": ""}, {"ticket": "2431349", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431349", "description": ""}, {"ticket": "2431350", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431350", "description": ""}, {"ticket": "2431352", "sourceBy": "Red Hat", "sourceLink":"https://bugzilla.redhat.com/show_bug.cgi?id=2431352", "description": ""}], "cves": [{"name": "CVE-2025-55130", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-55130", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "cvss3BaseScore": "7.1", "cwe": "CWE-281"}, {"name": "CVE-2025-55131", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-55131", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L", "cvss3BaseScore": "7.1", "cwe": "CWE-497"}, {"name": "CVE-2025-55132", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-55132", "cvss3ScoringVector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N", "cvss3BaseScore": "2.8", "cwe": "CWE-281"}, {"name": "CVE-2025-59465", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-59465", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-248"}, {"name": "CVE-2025-59466", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-59466", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.9", "cwe": "CWE-770"}, {"name": "CVE-2026-21637", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-21637", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.9", "cwe": "CWE-248"}], "references": [], "publishedAt": "2026-02-18T09:05:30.043251Z", "rpms": {"Rocky Linux 9": {"nvras": ["nodejs-nodemon-0:3.0.1-1.module+el9.7.0+40017+f0db1785.noarch.rpm", "nodejs-nodemon-0:3.0.1-1.module+el9.7.0+40018+a011993d.noarch.rpm", "nodejs-nodemon-0:3.0.1-1.module+el9.7.0+40022+9ecc286c.noarch.rpm", "nodejs-nodemon-0:3.0.1-1.module+el9.7.0+40017+f0db1785.src.rpm", "nodejs-nodemon-0:3.0.1-1.module+el9.7.0+40022+9ecc286c.src.rpm", "nodejs-nodemon-0:3.0.1-1.module+el9.7.0+40018+a011993d.src.rpm", "nodejs-packaging-0:2021.06-5.module+el9.7.0+40051+f2ef3f49.noarch.rpm","nodejs-packaging-0:2021.06-5.module+el9.7.0+40050+22a42328.noarch.rpm", "nodejs-packaging-0:2021.06-5.module+el9.7.0+40050+22a42328.src.rpm", "nodejs-packaging-0:2021.06-5.module+el9.7.0+40051+f2ef3f49.src.rpm", "nodejs-packaging-bundler-0:2021.06-5.module+el9.7.0+40051+f2ef3f49.noarch.rpm", "nodejs-packaging-bundler-0:2021.06-5.module+el9.7.0+40050+22a42328.noarch.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Node.js on Rocky Linux 9 gets important security updates addressing denial of service and filesystem permission issues.. nodejs updates, security advisory, Rocky Linux security, permissions bypass, denial of service. . Severity: Important. LinuxSecurity.com Team
Important: nodejs:22 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:2421", "synopsis": "Important: nodejs:22 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for nodejs, nodejs-nodemon, module.nodejs-packaging, module.nodejs, module.nodejs-nodemon.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. \n\nSecurity Fix(es):\n\n* nodejs: Nodejs filesystem permissions bypass (CVE-2025-55132)\n\n* nodejs: Nodejs denial of service (CVE-2026-21637)\n\n* nodejs: Nodejs denial of service (CVE-2025-59466)\n\n* nodejs: Nodejs denial of service (CVE-2025-59465)\n\n* nodejs: Nodejs uninitialized memory exposure (CVE-2025-55131)\n\n* nodejs: Nodejs file permissions bypass (CVE-2025-55130)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2431338", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431338", "description": ""}, {"ticket": "2431340", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431340", "description": ""}, {"ticket": "2431343", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431343", "description": ""}, {"ticket": "2431349", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431349", "description": ""}, {"ticket": "2431350", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431350", "description": ""}, {"ticket": "2431352", "sourceBy": "Red Hat", "sourceLink":"https://bugzilla.redhat.com/show_bug.cgi?id=2431352", "description": ""}], "cves": [{"name": "CVE-2025-55130", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-55130", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "cvss3BaseScore": "7.1", "cwe": "CWE-281"}, {"name": "CVE-2025-55131", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-55131", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L", "cvss3BaseScore": "7.1", "cwe": "CWE-497"}, {"name": "CVE-2025-55132", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-55132", "cvss3ScoringVector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N", "cvss3BaseScore": "2.8", "cwe": "CWE-281"}, {"name": "CVE-2025-59465", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-59465", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-248"}, {"name": "CVE-2025-59466", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-59466", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.9", "cwe": "CWE-770"}, {"name": "CVE-2026-21637", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-21637", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.9", "cwe": "CWE-248"}], "references": [], "publishedAt": "2026-02-11T09:10:35.649030Z", "rpms": {"Rocky Linux 8": {"nvras": ["nodejs-nodemon-0:3.0.1-1.module+el8.10.0+1667+4a788d89.src.rpm", "nodejs-nodemon-0:3.0.1-1.module+el8.10.0+1823+b5789597.src.rpm", "nodejs-nodemon-0:3.0.1-1.module+el8.10.0+1924+614dc87f.src.rpm", "nodejs-nodemon-0:3.0.1-1.module+el8.10.0+1935+d3cbe60f.src.rpm", "nodejs-nodemon-0:3.0.1-1.module+el8.10.0+1666+930e28e8.src.rpm", "nodejs-packaging-0:2021.06-5.module+el8.10.0+2084+ab509703.src.rpm", "nodejs-1:22.22.0-1.module+el8.10.0+40078+280dc7ce.aarch64.rpm","nodejs-1:22.22.0-1.module+el8.10.0+40078+280dc7ce.src.rpm", "nodejs-1:22.22.0-1.module+el8.10.0+40078+280dc7ce.x86_64.rpm", "nodejs-debuginfo-1:22.22.0-1.module+el8.10.0+40078+280dc7ce.aarch64.rpm", "nodejs-debuginfo-1:22.22.0-1.module+el8.10.0+40078+280dc7ce.x86_64.rpm", "nodejs-debugsource-1:22.22.0-1.module+el8.10.0+40078+280dc7ce.aarch64.rpm", "nodejs-debugsource-1:22.22.0-1.module+el8.10.0+40078+280dc7ce.x86_64.rpm", "nodejs-devel-1:22.22.0-1.module+el8.10.0+40078+280dc7ce.aarch64.rpm", "nodejs-devel-1:22.22.0-1.module+el8.10.0+40078+280dc7ce.x86_64.rpm", "nodejs-docs-1:22.22.0-1.module+el8.10.0+40078+280dc7ce.noarch.rpm", "nodejs-full-i18n-1:22.22.0-1.module+el8.10.0+40078+280dc7ce.aarch64.rpm", "nodejs-full-i18n-1:22.22.0-1.module+el8.10.0+40078+280dc7ce.x86_64.rpm", "nodejs-libs-1:22.22.0-1.module+el8.10.0+40078+280dc7ce.aarch64.rpm", "nodejs-libs-1:22.22.0-1.module+el8.10.0+40078+280dc7ce.x86_64.rpm", "nodejs-libs-debuginfo-1:22.22.0-1.module+el8.10.0+40078+280dc7ce.aarch64.rpm", "nodejs-libs-debuginfo-1:22.22.0-1.module+el8.10.0+40078+280dc7ce.x86_64.rpm", "nodejs-nodemon-0:3.0.1-1.module+el8.9.0+1760+903d54b9.noarch.rpm", "nodejs-nodemon-0:3.0.1-1.module+el8.10.0+1988+437f3d23.noarch.rpm", "nodejs-nodemon-0:3.0.1-1.module+el8.10.0+1989+e60144d9.noarch.rpm", "nodejs-nodemon-0:3.0.1-1.module+el8.10.0+1824+532140ee.noarch.rpm", "nodejs-nodemon-0:3.0.1-1.module+el8.10.0+1824+532140ee.src.rpm", "nodejs-nodemon-0:3.0.1-1.module+el8.9.0+1760+903d54b9.src.rpm", "nodejs-nodemon-0:3.0.1-1.module+el8.10.0+1988+437f3d23.src.rpm", "nodejs-nodemon-0:3.0.1-1.module+el8.10.0+1989+e60144d9.src.rpm", "npm-1:10.9.4-1.22.22.0.1.module+el8.10.0+40078+280dc7ce.aarch64.rpm", "npm-1:10.9.4-1.22.22.0.1.module+el8.10.0+40078+280dc7ce.x86_64.rpm", "v8-12.4-devel-3:12.4.254.21-1.22.22.0.1.module+el8.10.0+40078+280dc7ce.aarch64.rpm", "v8-12.4-devel-3:12.4.254.21-1.22.22.0.1.module+el8.10.0+40078+280dc7ce.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Node.js security update for Rocky Linux addresses criticalissues affecting system performance and data integrity.. nodejs updates, security fixes, important advisory. . Severity: Important. LinuxSecurity.com Team
Arbitrary JavaScript execution in PDF.js. (CVE-2024-4367) IndexedDB files retained in private browsing mode. (CVE-2024-4767) Potential permissions request bypass via clickjacking. (CVE-2024-4768) Cross-origin responses could be distinguished between script and non-script content-types. (CVE-2024-4769) . MGASA-2024-0191 - Updated thunderbird packages fix security vulnerabilities Publication date: 21 May 2024 URL: https://advisories.mageia.org/MGASA-2024-0191.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-4367, CVE-2024-4767, CVE-2024-4768, CVE-2024-4769, CVE-2024-4770, CVE-2024-4777 Arbitrary JavaScript execution in PDF.js. (CVE-2024-4367) IndexedDB files retained in private browsing mode. (CVE-2024-4767) Potential permissions request bypass via clickjacking. (CVE-2024-4768) Cross-origin responses could be distinguished between script and non-script content-types. (CVE-2024-4769) Use-after-free could occur when printing to PDF. (CVE-2024-4770) Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. (CVE-2024-4777) References: - https://bugs.mageia.org/show_bug.cgi?id=33218 - https://www.thunderbird.net/en-US/thunderbird/115.11.0esr/releasenotes/ - https://www.mozilla.org/en-US/security/advisories/mfsa2024-23/ - https://www.cve.org/CVERecord?id=CVE-2024-4367 - https://www.cve.org/CVERecord?id=CVE-2024-4767 - https://www.cve.org/CVERecord?id=CVE-2024-4768 - https://www.cve.org/CVERecord?id=CVE-2024-4769 - https://www.cve.org/CVERecord?id=CVE-2024-4770 - https://www.cve.org/CVERecord?id=CVE-2024-4777 SRPMS: - 9/core/thunderbird-115.11.0-1.mga9 - 9/core/thunderbird-l10n-115.11.0-1.mga9 . Mozilla Thunderbird version 115.11 includes crucial updates addressing several vulnerabilities related to JavaScript execution and permission bypass vulnerabilities.. Thunderbird Security Advisory, Mageia Updates, JavaScript Execution Fixes, Clickjacking Issues. . Severity: Critical. LinuxSecurity.com Team
An update for nodejs is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: nodejs security, bug fix, and enhancement update Advisory ID: RHSA-2023:5533-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:5533 Issue date: 2023-10-09 CVE Names: CVE-2022-4904 CVE-2022-25881 CVE-2023-23920 CVE-2023-23936 CVE-2023-24807 CVE-2023-30581 CVE-2023-30588 CVE-2023-30589 CVE-2023-30590 CVE-2023-32002 CVE-2023-32006 CVE-2023-32559 ===================================================================== 1. Summary: An update for nodejs is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.9.0) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. The package has been upgraded to a later upstream version: nodejs (16.20.2). Security Fix(es): * nodejs: Permissions policies can be bypassed via Module._load (CVE-2023-32002) * c-ares: buffer overflow in config_sortlist() due to missing string length check (CVE-2022-4904) * http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability (CVE-2022-25881) * Node.js:Fetch API did not protect against CRLF injection in host headers (CVE-2023-23936) * nodejs: mainModule.proto bypass experimental policy mechanism (CVE-2023-30581) * nodejs: process interuption due to invalid Public Key information in x509 certificates (CVE-2023-30588) * nodejs: HTTP Request Smuggling via Empty headers separated by CR (CVE-2023-30589) * nodejs: DiffieHellman do not generate keys after setting a private key (CVE-2023-30590) * nodejs: Permissions policies can impersonate other modules in using module.constructor.createRequire() (CVE-2023-32006) * nodejs: Permissions policies can be bypassed via process.binding (CVE-2023-32559) * Node.js: insecure loading of ICU data through ICU_DATA environment variable (CVE-2023-23920) * Node.js: Regular Expression Denial of Service in Headers fetch API (CVE-2023-24807) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * nodejs: Rebase to the latest Nodejs 16 release [rhel-9] (BZ#2236435, BZ#2178078, BZ#2223335) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2165824 - CVE-2022-25881 http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability 2168631 - CVE-2022-4904 c-ares: buffer overflow in config_sortlist() due to missing string length check 2172190 - CVE-2023-23936 Node.js: Fetch API did not protect against CRLF injection in host headers 2172204 - CVE-2023-24807 Node.js: Regular Expression Denial of Service in Headers fetch API 2172217 - CVE-2023-23920 Node.js: insecure loading of ICU data through ICU_DATA environment variable 2178078 - nodejs: Rebase to the latest Nodejs 16 release [rhel-9] [rhel-9.0.0.z] 2219824 - CVE-2023-30581 nodejs: mainModule.proto bypass experimental policy mechanism 2219838 - CVE-2023-30588nodejs: process interuption due to invalid Public Key information in x509 certificates 2219841 - CVE-2023-30589 nodejs: HTTP Request Smuggling via Empty headers separated by CR 2219842 - CVE-2023-30590 nodejs: DiffieHellman do not generate keys after setting a private key 2223335 - nodejs: Rebase to the latest Nodejs 16 release [rhel-9] [rhel-9.0.0.z] 2230948 - CVE-2023-32002 nodejs: Permissions policies can be bypassed via Module._load 2230955 - CVE-2023-32006 nodejs: Permissions policies can impersonate other modules in using module.constructor.createRequire() 2230956 - CVE-2023-32559 nodejs: Permissions policies can be bypassed via process.binding 2236435 - nodejs: Rebase to the latest Nodejs 16 release [rhel-9] [rhel-9.0.0.z] 6. Package List: Red Hat Enterprise Linux AppStream EUS(v.9.0): Source: nodejs-16.20.2-1.el9_0.src.rpm aarch64: nodejs-16.20.2-1.el9_0.aarch64.rpm nodejs-debuginfo-16.20.2-1.el9_0.aarch64.rpm nodejs-debugsource-16.20.2-1.el9_0.aarch64.rpm nodejs-full-i18n-16.20.2-1.el9_0.aarch64.rpm nodejs-libs-16.20.2-1.el9_0.aarch64.rpm nodejs-libs-debuginfo-16.20.2-1.el9_0.aarch64.rpm npm-8.19.4-1.16.20.2.1.el9_0.aarch64.rpm noarch: nodejs-docs-16.20.2-1.el9_0.noarch.rpm ppc64le: nodejs-16.20.2-1.el9_0.ppc64le.rpm nodejs-debuginfo-16.20.2-1.el9_0.ppc64le.rpm nodejs-debugsource-16.20.2-1.el9_0.ppc64le.rpm nodejs-full-i18n-16.20.2-1.el9_0.ppc64le.rpm nodejs-libs-16.20.2-1.el9_0.ppc64le.rpm nodejs-libs-debuginfo-16.20.2-1.el9_0.ppc64le.rpm npm-8.19.4-1.16.20.2.1.el9_0.ppc64le.rpm s390x: nodejs-16.20.2-1.el9_0.s390x.rpm nodejs-debuginfo-16.20.2-1.el9_0.s390x.rpm nodejs-debugsource-16.20.2-1.el9_0.s390x.rpm nodejs-full-i18n-16.20.2-1.el9_0.s390x.rpm nodejs-libs-16.20.2-1.el9_0.s390x.rpm nodejs-libs-debuginfo-16.20.2-1.el9_0.s390x.rpm npm-8.19.4-1.16.20.2.1.el9_0.s390x.rpm x86_64: nodejs-16.20.2-1.el9_0.x86_64.rpm nodejs-debuginfo-16.20.2-1.el9_0.i686.rpm nodejs-debuginfo-16.20.2-1.el9_0.x86_64.rpm nodejs-debugsource-16.20.2-1.el9_0.i686.rpm nodejs-debugsource-16.20.2-1.el9_0.x86_64.rpm nodejs-full-i18n-16.20.2-1.el9_0.x86_64.rpm nodejs-libs-16.20.2-1.el9_0.i686.rpm nodejs-libs-16.20.2-1.el9_0.x86_64.rpm nodejs-libs-debuginfo-16.20.2-1.el9_0.i686.rpm nodejs-libs-debuginfo-16.20.2-1.el9_0.x86_64.rpm npm-8.19.4-1.16.20.2.1.el9_0.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2022-4904 https://access.redhat.com/security/cve/CVE-2022-25881 https://access.redhat.com/security/cve/CVE-2023-23920 https://access.redhat.com/security/cve/CVE-2023-23936 https://access.redhat.com/security/cve/CVE-2023-24807 https://access.redhat.com/security/cve/CVE-2023-30581 https://access.redhat.com/security/cve/CVE-2023-30588 https://access.redhat.com/security/cve/CVE-2023-30589 https://access.redhat.com/security/cve/CVE-2023-30590 https://access.redhat.com/security/cve/CVE-2023-32002 https://access.redhat.com/security/cve/CVE-2023-32006 https://access.redhat.com/security/cve/CVE-2023-32559 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJlJBvKAAoJENzjgjWX9erEaZkP/3RkSS6TB+iV2kfP0PG4x594 rLzFxFsAe7yMsm2sEa4KeG10tRkuQ2hUG5VoAsypMYO7pkoQGwd5jzoWHHDP4L3m j7G/Mfv/1sF6a5ga2zodLc7eWrzPrgDn0ma7KDDBq04Q5BZBaLNreJ5P0DF+LQtN utnqiqvvtH0YwR2aYskn0huk4n85WBtnjDpRIN4EBM8J6zhswxvBG0JFjEIwvNQx vNzvVwZvpCQxyvEko5rjc3RbtpXZkJCWsN26tZ8AeYDl4Fa0x9g+GtM1cKVsprTM fMubzaTqxd0FvySIIVE6Miy9drCzcWPAmFnGfWOaaxhUbJesaHM3xCgocaIocFGS h7e6NxaVf7xAesB2iRCGW/F6z/EghGJDWoTBcfVG9qsutJ0UBrzT3+A6uTPCuLd/ NIGbZHFlaxls3hSNufzDkRU4qNj5yjOn2Q/hb2Dc33fc7OGfBWAKVU0P7uGPcRfd piG+VaE+C8SHiKIiKxh5S0F4vARqEwxuvXoo4fdowQIqxrxsdYyFzQMdam8HPorr ++5VziXZp3c3SNivhK5haWigEI4K0vFveU+wXlvgMt2ZvpMR0wW+WYzM1WRrFSIC tZ2Lwoxqn4+plgxq0yKaDcCa1VVINNYls+sRQ0Kf0VnspuguM9pn7i9Pfctxg+uY Cf7azydGontW3r5G2DZl =D1Bm -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for the nodejs:16 module is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: nodejs:16 security, bug fix, and enhancement update Advisory ID: RHSA-2023:5361-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:5361 Issue date: 2023-09-26 CVE Names: CVE-2022-25883 CVE-2023-30581 CVE-2023-30588 CVE-2023-30589 CVE-2023-30590 CVE-2023-32002 CVE-2023-32006 CVE-2023-32559 ===================================================================== 1. Summary: An update for the nodejs:16 module is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.8.6) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. The following packages have been upgraded to a later upstream version: nodejs (16). (BZ#2223679, BZ#2223681, BZ#2223683, BZ#2223685, BZ#2223687, BZ#2233892) Security Fix(es): * nodejs: Permissions policies can be bypassed via Module._load (CVE-2023-32002) * nodejs-semver: Regular expression denial of service (CVE-2022-25883) * nodejs: mainModule.proto bypass experimental policy mechanism (CVE-2023-30581) * nodejs: processinteruption due to invalid Public Key information in x509 certificates (CVE-2023-30588) * nodejs: HTTP Request Smuggling via Empty headers separated by CR (CVE-2023-30589) * nodejs: DiffieHellman do not generate keys after setting a private key (CVE-2023-30590) * nodejs: Permissions policies can impersonate other modules in using module.constructor.createRequire() (CVE-2023-32006) * nodejs: Permissions policies can be bypassed via process.binding (CVE-2023-32559) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * nodejs:16/nodejs: nodejs.prov doesn't generate the bundled dependency for modules starting @ like @colors/colors (BZ#2237395) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2216475 - CVE-2022-25883 nodejs-semver: Regular expression denial of service 2219824 - CVE-2023-30581 nodejs: mainModule.proto bypass experimental policy mechanism 2219838 - CVE-2023-30588 nodejs: process interuption due to invalid Public Key information in x509 certificates 2219841 - CVE-2023-30589 nodejs: HTTP Request Smuggling via Empty headers separated by CR 2219842 - CVE-2023-30590 nodejs: DiffieHellman do not generate keys after setting a private key 2223679 - nodejs:16/nodejs: Rebase to the latest Nodejs 16 release [rhel-8] [rhel-8.6.0.z] 2230948 - CVE-2023-32002 nodejs: Permissions policies can be bypassed via Module._load 2230955 - CVE-2023-32006 nodejs: Permissions policies can impersonate other modules in using module.constructor.createRequire() 2230956 - CVE-2023-32559 nodejs: Permissions policies can be bypassed via process.binding 2233892 - nodejs:16/nodejs: Rebase to the latest Nodejs 16 release [rhel-8] [rhel-8.6.0.z] 2237395 - nodejs:16/nodejs: nodejs.prov doesn't generate the bundled dependencyfor modules starting @ like @colors/colors [rhel-8.6.0.z] 6. Package List: Red Hat Enterprise Linux AppStream EUS(v.8.6): Source: nodejs-16.20.2-2.module+el8.6.0+19897+9590a839.src.rpm nodejs-nodemon-3.0.1-1.module+el8.6.0+19765+366b9144.src.rpm nodejs-packaging-26-1.module+el8.6.0+19856+c0c87259.src.rpm aarch64: nodejs-16.20.2-2.module+el8.6.0+19897+9590a839.aarch64.rpm nodejs-debuginfo-16.20.2-2.module+el8.6.0+19897+9590a839.aarch64.rpm nodejs-debugsource-16.20.2-2.module+el8.6.0+19897+9590a839.aarch64.rpm nodejs-devel-16.20.2-2.module+el8.6.0+19897+9590a839.aarch64.rpm nodejs-full-i18n-16.20.2-2.module+el8.6.0+19897+9590a839.aarch64.rpm npm-8.19.4-1.16.20.2.2.module+el8.6.0+19897+9590a839.aarch64.rpm noarch: nodejs-docs-16.20.2-2.module+el8.6.0+19897+9590a839.noarch.rpm nodejs-nodemon-3.0.1-1.module+el8.6.0+19765+366b9144.noarch.rpm nodejs-packaging-26-1.module+el8.6.0+19856+c0c87259.noarch.rpm ppc64le: nodejs-16.20.2-2.module+el8.6.0+19897+9590a839.ppc64le.rpm nodejs-debuginfo-16.20.2-2.module+el8.6.0+19897+9590a839.ppc64le.rpm nodejs-debugsource-16.20.2-2.module+el8.6.0+19897+9590a839.ppc64le.rpm nodejs-devel-16.20.2-2.module+el8.6.0+19897+9590a839.ppc64le.rpm nodejs-full-i18n-16.20.2-2.module+el8.6.0+19897+9590a839.ppc64le.rpm npm-8.19.4-1.16.20.2.2.module+el8.6.0+19897+9590a839.ppc64le.rpm s390x: nodejs-16.20.2-2.module+el8.6.0+19897+9590a839.s390x.rpm nodejs-debuginfo-16.20.2-2.module+el8.6.0+19897+9590a839.s390x.rpm nodejs-debugsource-16.20.2-2.module+el8.6.0+19897+9590a839.s390x.rpm nodejs-devel-16.20.2-2.module+el8.6.0+19897+9590a839.s390x.rpm nodejs-full-i18n-16.20.2-2.module+el8.6.0+19897+9590a839.s390x.rpm npm-8.19.4-1.16.20.2.2.module+el8.6.0+19897+9590a839.s390x.rpm x86_64: nodejs-16.20.2-2.module+el8.6.0+19897+9590a839.x86_64.rpm nodejs-debuginfo-16.20.2-2.module+el8.6.0+19897+9590a839.x86_64.rpm nodejs-debugsource-16.20.2-2.module+el8.6.0+19897+9590a839.x86_64.rpm nodejs-devel-16.20.2-2.module+el8.6.0+19897+9590a839.x86_64.rpm nodejs-full-i18n-16.20.2-2.module+el8.6.0+19897+9590a839.x86_64.rpm npm-8.19.4-1.16.20.2.2.module+el8.6.0+19897+9590a839.x86_64.rpm These packages are GPG signed by Red Hatfor security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-25883 https://access.redhat.com/security/cve/CVE-2023-30581 https://access.redhat.com/security/cve/CVE-2023-30588 https://access.redhat.com/security/cve/CVE-2023-30589 https://access.redhat.com/security/cve/CVE-2023-30590 https://access.redhat.com/security/cve/CVE-2023-32002 https://access.redhat.com/security/cve/CVE-2023-32006 https://access.redhat.com/security/cve/CVE-2023-32559 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJlEvhMAAoJENzjgjWX9erEi5IP/jdC6ZeTw1731qcDvIwRJBMw vW4r9w8sp33RdM+kdyeXnvCf8saD6ipc9hmE6tkBGXbx9o9hUq6dbkYkAHSUQN+s 3oI8UJU6FaLYrfB7LHYgNWJYlvdLJ7ZmSq8EG/LkCezsvJOCl7BczHtRTR9NQx9l fZGV3jeGnH/A9rts/zVaEnnf4pIqXTOeEm67GtHkscrS22cMZDQ0qsJ7+3068Oxe NuuqW2mXnBGy3fomdxUqoWVqOtqbxRK+RoXQc3s4acyM0nSZwjWF+ZITR1Fd9BKh VpTWV1jNWZ9ZNsUhIiEOEMyS2FcLt+3VFHsQzs2PtiD6R/AiY3BihqDsjljGt1IX HE5627aG2uu5hq3XYxDgsbQecBAA7QbwrN+eGF2YTsPC6GFGtP4A+SGwQvE9LQR8 V1aGfX7xiE8JcaMsSuqSkuhPVb0XyCfidcv9EuN8iqnfWL0cwUZeuo/oiPxpB1Tl CXpVoZuUeUcRRUYMW1Gw0wtL0UBPE4V645ysAMuAFyIgO2h8IFxDnF2j3tdQq7cE lNvG7ZFmLNtzi5cg7iX0t7dm0MA85r98QOh+7M41g2GwgAkeCqmOaznTgbrUmUPD bnGxJ3wSih1VJ/MlAfQLhFb39kfJj6cj33d7XBCM8aF0EnhQ5JKISSO2bTQYHbQY BhztaX0whwtE9+G9HxIg =1KUc -----END PGP SIGNATURE----- -- RHSA-announce mailing list
This update for nodejs12 fixes the following issues: CVE-2023-23918: Fixed permissions policies bypass via process.mainModule (bsc#1208481).. # Security update for nodejs12 Announcement ID: SUSE-SU-2023:3455-1 Rating: important References: * #1208481 * #1212574 * #1212582 * #1212583 * #1214150 * #1214154 * #1214156 Cross-References: * CVE-2023-23918 * CVE-2023-30581 * CVE-2023-30589 * CVE-2023-30590 * CVE-2023-32002 * CVE-2023-32006 * CVE-2023-32559 CVSS scores: * CVE-2023-23918 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2023-23918 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2023-30581 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-30589 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2023-30589 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2023-30590 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2023-32002 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:H * CVE-2023-32002 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-32006 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2023-32006 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-32559 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L Affected Products: * openSUSE Leap 15.4 * SUSE Enterprise Storage 7 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server for SAPApplications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Manager Server 4.2 An update that solves seven vulnerabilities can now be installed. ## Description: This update for nodejs12 fixes the following issues: * CVE-2023-23918: Fixed permissions policies bypass via process.mainModule (bsc#1208481). * CVE-2023-32002: Fixed permissions policies bypass via Module._load (bsc#1214150). * CVE-2023-32006: Fixed permissions policies impersonation using module.constructor.createRequire() (bsc#1214156). * CVE-2023-32559: Fixed permissions policies bypass via process.binding (bsc#1214154). * CVE-2023-30581: Fixed mainModule.proto bypass (bsc#1212574). * CVE-2023-30590: Fixed missing DiffieHellman key generation (bsc#1212583). * CVE-2023-30589: Fixed HTTP Request Smuggling via Empty headers separated by CR (bsc#1212582). ## Patch Instructions: To install this SUSE Important update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2023-3455=1 * SUSE Manager Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.2-2023-3455=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2023-3455=1 * SUSE Enterprise Storage 7 zypper in -t patch SUSE-Storage-7-2023-3455=1 * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-3455=1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2023-3455=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-ESPOS-2023-3455=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2023-3455=1 * SUSE Linux EnterpriseServer 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2023-3455=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2023-3455=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2023-3455=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * nodejs12-devel-12.22.12-150200.4.50.1 * nodejs12-debuginfo-12.22.12-150200.4.50.1 * npm12-12.22.12-150200.4.50.1 * nodejs12-debugsource-12.22.12-150200.4.50.1 * nodejs12-12.22.12-150200.4.50.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * nodejs12-docs-12.22.12-150200.4.50.1 * SUSE Manager Server 4.2 (ppc64le s390x x86_64) * nodejs12-devel-12.22.12-150200.4.50.1 * nodejs12-debuginfo-12.22.12-150200.4.50.1 * npm12-12.22.12-150200.4.50.1 * nodejs12-debugsource-12.22.12-150200.4.50.1 * nodejs12-12.22.12-150200.4.50.1 * SUSE Manager Server 4.2 (noarch) * nodejs12-docs-12.22.12-150200.4.50.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * nodejs12-devel-12.22.12-150200.4.50.1 * nodejs12-debuginfo-12.22.12-150200.4.50.1 * npm12-12.22.12-150200.4.50.1 * nodejs12-debugsource-12.22.12-150200.4.50.1 * nodejs12-12.22.12-150200.4.50.1 * SUSE Enterprise Storage 7.1 (noarch) * nodejs12-docs-12.22.12-150200.4.50.1 * SUSE Enterprise Storage 7 (aarch64 x86_64) * nodejs12-devel-12.22.12-150200.4.50.1 * nodejs12-debuginfo-12.22.12-150200.4.50.1 * npm12-12.22.12-150200.4.50.1 * nodejs12-debugsource-12.22.12-150200.4.50.1 * nodejs12-12.22.12-150200.4.50.1 * SUSE Enterprise Storage 7 (noarch) * nodejs12-docs-12.22.12-150200.4.50.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * nodejs12-devel-12.22.12-150200.4.50.1 * nodejs12-debuginfo-12.22.12-150200.4.50.1 * npm12-12.22.12-150200.4.50.1 * nodejs12-debugsource-12.22.12-150200.4.50.1 * nodejs12-12.22.12-150200.4.50.1 * openSUSE Leap 15.4 (noarch) * nodejs12-docs-12.22.12-150200.4.50.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64 x86_64) * nodejs12-devel-12.22.12-150200.4.50.1 * nodejs12-debuginfo-12.22.12-150200.4.50.1 * npm12-12.22.12-150200.4.50.1 * nodejs12-debugsource-12.22.12-150200.4.50.1 * nodejs12-12.22.12-150200.4.50.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (noarch) * nodejs12-docs-12.22.12-150200.4.50.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (aarch64 x86_64) * nodejs12-devel-12.22.12-150200.4.50.1 * nodejs12-debuginfo-12.22.12-150200.4.50.1 * npm12-12.22.12-150200.4.50.1 * nodejs12-debugsource-12.22.12-150200.4.50.1 * nodejs12-12.22.12-150200.4.50.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (noarch) * nodejs12-docs-12.22.12-150200.4.50.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * nodejs12-devel-12.22.12-150200.4.50.1 * nodejs12-debuginfo-12.22.12-150200.4.50.1 * npm12-12.22.12-150200.4.50.1 * nodejs12-debugsource-12.22.12-150200.4.50.1 * nodejs12-12.22.12-150200.4.50.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * nodejs12-docs-12.22.12-150200.4.50.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x x86_64) * nodejs12-devel-12.22.12-150200.4.50.1 * nodejs12-debuginfo-12.22.12-150200.4.50.1 * npm12-12.22.12-150200.4.50.1 * nodejs12-debugsource-12.22.12-150200.4.50.1 * nodejs12-12.22.12-150200.4.50.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (noarch) * nodejs12-docs-12.22.12-150200.4.50.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * nodejs12-devel-12.22.12-150200.4.50.1 * nodejs12-debuginfo-12.22.12-150200.4.50.1 * npm12-12.22.12-150200.4.50.1 *nodejs12-debugsource-12.22.12-150200.4.50.1 * nodejs12-12.22.12-150200.4.50.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (noarch) * nodejs12-docs-12.22.12-150200.4.50.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) * nodejs12-devel-12.22.12-150200.4.50.1 * nodejs12-debuginfo-12.22.12-150200.4.50.1 * npm12-12.22.12-150200.4.50.1 * nodejs12-debugsource-12.22.12-150200.4.50.1 * nodejs12-12.22.12-150200.4.50.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (noarch) * nodejs12-docs-12.22.12-150200.4.50.1 ## References: * https://www.suse.com/security/cve/CVE-2023-23918.html * https://www.suse.com/security/cve/CVE-2023-30581.html * https://www.suse.com/security/cve/CVE-2023-30589.html * https://www.suse.com/security/cve/CVE-2023-30590.html * https://www.suse.com/security/cve/CVE-2023-32002.html * https://www.suse.com/security/cve/CVE-2023-32006.html * https://www.suse.com/security/cve/CVE-2023-32559.html * https://bugzilla.suse.com/show_bug.cgi?id=1208481 * https://bugzilla.suse.com/show_bug.cgi?id=1212574 * https://bugzilla.suse.com/show_bug.cgi?id=1212582 * https://bugzilla.suse.com/show_bug.cgi?id=1212583 * https://bugzilla.suse.com/show_bug.cgi?id=1214150 * https://bugzilla.suse.com/show_bug.cgi?id=1214154 * https://bugzilla.suse.com/show_bug.cgi?id=1214156 . Critical patch released for nodejs12 enhancing permission protocols. Ensure your system's safety with this new update.. openSUSE Nodejs12 Patch, permissions security fix, nodejs permissions issues. . Severity: Important. LinuxSecurity.com Team
This update upgrades Thunderbird to version 102.14.0. * Mozilla: Offscreen Canvas could have bypassed cross-origin restrictions (CVE-2023-4045) * Mozilla: Incorrect value used during WASM compilation (CVE-2023-4046) * Mozilla: Potential permissions request bypass via clickjacking (CVE-2023-4047) * Mozilla: Crash in DOMParser due to out-of-memory conditions (CVE-2023-4048) * Mozilla: Fix pot [More...]. Synopsis: Important: thunderbird security update Advisory ID: SLSA-2023:4495-1 Issue Date: 2023-08-07 CVE Numbers: CVE-2023-4045 CVE-2023-4046 CVE-2023-4047 CVE-2023-4048 CVE-2023-4049 CVE-2023-4050 CVE-2023-4055 CVE-2023-4056 CVE-2023-4057 CVE-2023-3417 -- This update upgrades Thunderbird to version 102.14.0. Security Fix(es): * Mozilla: Offscreen Canvas could have bypassed cross-origin restrictions (CVE-2023-4045) * Mozilla: Incorrect value used during WASM compilation (CVE-2023-4046) * Mozilla: Potential permissions request bypass via clickjacking (CVE-2023-4047) * Mozilla: Crash in DOMParser due to out-of-memory conditions (CVE-2023-4048) * Mozilla: Fix potential race conditions when releasing platform objects (CVE-2023-4049) * Mozilla: Stack buffer overflow in StorageManager (CVE-2023-4050) * Mozilla: Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1, Firefox ESR 102.14, Thunderbird 115.1, and Thunderbird 102.14 (CVE-2023-4056) * Mozilla: Memory safety bugs fixed in Firefox ESR 115.1, and Thunderbird 115.1 (CVE-2023-4057) * thunderbird: File Extension Spoofing using the Text Direction Override Character (CVE-2023-3417) * Mozilla: Cookie jar overflow caused unexpected cookie jar state (CVE-2023-4055) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 thunderbird-102.14.0-1.el7_9.x86_64.rpm thunderbird-debuginfo-102.14.0-1.el7_9.x86_64.rpm - Scientific Linux Development Team . Firefox technical update SLSA-2023:4495-1 strengthens defenses against a range of attacks and security flaws.. Thunderbird Update, Security Patch SL7, Mozilla Fixes. . Severity: Critical. LinuxSecurity.com Team
This update upgrades Thunderbird to version 102.11.0. * Mozilla: Browser prompts could have been obscured by popups (CVE-2023-32205) * Mozilla: Crash in RLBox Expat driver (CVE-2023-32206) * Mozilla: Potential permissions request bypass via clickjacking (CVE-2023-32207) * Mozilla: Memory safety bugs fixed in Firefox 113 and Firefox ESR 102.11 (CVE-2023-32215) * Mozilla: Content process cras [More...]. Synopsis: Important: thunderbird security update Advisory ID: SLSA-2023:3151-1 Issue Date: 2023-05-17 CVE Numbers: CVE-2023-32205 CVE-2023-32206 CVE-2023-32207 CVE-2023-32211 CVE-2023-32212 CVE-2023-32213 CVE-2023-32215 -- This update upgrades Thunderbird to version 102.11.0. Security Fix(es): * Mozilla: Browser prompts could have been obscured by popups (CVE-2023-32205) * Mozilla: Crash in RLBox Expat driver (CVE-2023-32206) * Mozilla: Potential permissions request bypass via clickjacking (CVE-2023-32207) * Mozilla: Memory safety bugs fixed in Firefox 113 and Firefox ESR 102.11 (CVE-2023-32215) * Mozilla: Content process crash due to invalid wasm code (CVE-2023-32211) * Mozilla: Potential spoof due to obscured address bar (CVE-2023-32212) * Mozilla: Potential memory corruption in FileReader::DoReadData() (CVE-2023-32213) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 thunderbird-102.11.0-1.el7_9.x86_64.rpm thunderbird-debuginfo-102.11.0-1.el7_9.x86_64.rpm - Scientific Linux Development Team . Important Thunderbird patch for SL7.x x86_64 addresses multiple vulnerabilities, including data integrity flaws and privilege escalation.. Thunderbird Update, Mozilla Security, Scientific Linux Advisory, Browser Security Update. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.