Release Info

Advisory: CLSA-2025:1754412086

OS: AlmaLinux 9.2 ESU

Public date: 2025-08-05 16:41:28.203707

Project: nodejs

Version: 16.20.2-3.el9_2.tuxcare.els3

Errata link: https://errata.tuxcare.com/els_os/almalinux9.2esu/CLSA-2025-1754412086.html

Changelog

- CVE-2024-22019: fix resource exhaustion and DoS vulnerability by limiting number of bytes read from a single connection when handling HTTP requests with chunked encoding

Update

Update command: dnf update nodejs*

Packages list

nodejs-16.20.2-3.el9_2.tuxcare.els3.x86_64.rpm nodejs-devel-16.20.2-3.el9_2.tuxcare.els3.x86_64.rpm nodejs-docs-16.20.2-3.el9_2.tuxcare.els3.noarch.rpm nodejs-full-i18n-16.20.2-3.el9_2.tuxcare.els3.x86_64.rpm nodejs-libs-16.20.2-3.el9_2.tuxcare.els3.i686.rpm nodejs-libs-16.20.2-3.el9_2.tuxcare.els3.x86_64.rpm npm-8.19.4_1.16.20.2-3.el9_2.tuxcare.els3.x86_64.rpm v8-devel-9.4.146.26_1.16.20.2-3.el9_2.tuxcare.els3.x86_64.rpm

CVEs

CVE-2024-22019