Release Info

Advisory: CLSA-2025:1756305640

OS: AlmaLinux 9.2 ESU

Public date: 2025-08-27 14:40:42.143796

Project: nodejs

Version: 16.20.2-3.el9_2.tuxcare.els7

Errata link: https://errata.tuxcare.com/els_os/almalinux9.2esu/CLSA-2025-1756305640.html

Changelog

- CVE-2024-28863: prevent extraction in excessively deep sub-folders to address unlimited sub-folders vulnerability

Update

Update command: dnf update nodejs*

Packages list

nodejs-16.20.2-3.el9_2.tuxcare.els7.x86_64.rpm nodejs-devel-16.20.2-3.el9_2.tuxcare.els7.x86_64.rpm nodejs-docs-16.20.2-3.el9_2.tuxcare.els7.noarch.rpm nodejs-full-i18n-16.20.2-3.el9_2.tuxcare.els7.x86_64.rpm nodejs-libs-16.20.2-3.el9_2.tuxcare.els7.i686.rpm nodejs-libs-16.20.2-3.el9_2.tuxcare.els7.x86_64.rpm npm-8.19.4_1.16.20.2-3.el9_2.tuxcare.els7.x86_64.rpm v8-devel-9.4.146.26_1.16.20.2-3.el9_2.tuxcare.els7.x86_64.rpm

CVEs

CVE-2024-28863
CVE-2025-23085