|
|
Subscribe / Log in / New account

Mageia alert MGASA-2025-0041 (nodejs)

From:  Mageia Updates <updates-announce@ml.mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2025-0041: Updated nodejs packages fix security vulnerabilities
Date:  Fri, 07 Feb 2025 20:46:33 +0100
Message-ID:  <20250207194633.3C957A0083@duvel.mageia.org>
Archive-link:  Article

MGASA-2025-0041 - Updated nodejs packages fix security vulnerabilities Publication date: 07 Feb 2025 URL: https://advisories.mageia.org/MGASA-2025-0041.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-23083, CVE-2025-23085 Description: Worker permission bypass via InternalWorker leak in diagnostics. (CVE-2025-23083) GOAWAY HTTP/2 frames cause memory leak outside heap. (CVE-2025-23085) References: - https://bugs.mageia.org/show_bug.cgi?id=33947 - https://nodejs.org/en/blog/vulnerability/january-2025-sec... - https://www.openwall.com/lists/oss-security/2025/01/21/5 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-2... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-2... SRPMS: - 9/core/nodejs-22.13.1-2.mga9


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds