Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-11803

Опубликовано: 28 июл. 2025
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2025-11803: nodejs:22 security update (IMPORTANT)

nodejs [1:22.16.0-2]

  • Patch fix for sqlite CVE-2025-6965 Resolves: RHEL-103835

[1:22.15-1-1]

  • Update to 22.16.0 Fixes: CVE-2025-23166
  • Resolves: RHEL-91596 RHEL-92859

[1:22.15.0-1]

  • Update to 22.15.0
  • Drop upstream patches

[1:22.13.1-4]

  • Patch fix for sqlite CVE-2025-31498 Resolves: RHEL-87300

[1:22.13.1-3]

  • Update c-ares to newest version with fix for CVE-2025-31498 Resolves: RHEL-86581

[1:22.13.1-2]

  • Remove obsolete lua pretransaction script from spec file Resolves: RHEL-81117 RHEL-71410
  • Disable npm update notifications for users Resolves: RHEL-81080

[22.13.1-1]

  • Upgrade to version 22.13.1 Fixes CVE-2025-23083 CVE-2025-23085 CVE-2025-22150 Resolves: RHEL-76362 RHEL-76897

[22.11.0-1]

  • Upgrade to nodejs 22.11.0. Resolves: RHEL-35991

[22.4.1-4]

  • Exclude ix86 arches from building. Related: RHEL-35991

[22.4.1-4]

  • Initial import of nodeJS 22 Resolves: RHEL-35991

nodejs-nodemon nodejs-packaging

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module nodejs:22 is enabled

nodejs

22.16.0-2.module+el8.10.0+90633+72602921

nodejs-devel

22.16.0-2.module+el8.10.0+90633+72602921

nodejs-docs

22.16.0-2.module+el8.10.0+90633+72602921

nodejs-full-i18n

22.16.0-2.module+el8.10.0+90633+72602921

nodejs-libs

22.16.0-2.module+el8.10.0+90633+72602921

nodejs-nodemon

3.0.1-1.module+el8.10.0+90633+72602921

nodejs-packaging

2021.06-4.module+el8.10.0+90633+72602921

nodejs-packaging-bundler

2021.06-4.module+el8.10.0+90633+72602921

npm

10.9.2-1.22.16.0.2.module+el8.10.0+90633+72602921

v8-12.4-devel

12.4.254.21-1.22.16.0.2.module+el8.10.0+90633+72602921

Oracle Linux x86_64

Module nodejs:22 is enabled

nodejs

22.16.0-2.module+el8.10.0+90633+72602921

nodejs-devel

22.16.0-2.module+el8.10.0+90633+72602921

nodejs-docs

22.16.0-2.module+el8.10.0+90633+72602921

nodejs-full-i18n

22.16.0-2.module+el8.10.0+90633+72602921

nodejs-libs

22.16.0-2.module+el8.10.0+90633+72602921

nodejs-nodemon

3.0.1-1.module+el8.10.0+90633+72602921

nodejs-packaging

2021.06-4.module+el8.10.0+90633+72602921

nodejs-packaging-bundler

2021.06-4.module+el8.10.0+90633+72602921

npm

10.9.2-1.22.16.0.2.module+el8.10.0+90633+72602921

v8-12.4-devel

12.4.254.21-1.22.16.0.2.module+el8.10.0+90633+72602921

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
19 дней назад

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.

CVSS3: 7.7
redhat
19 дней назад

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.

CVSS3: 9.8
nvd
19 дней назад

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.

CVSS3: 9.8
debian
19 дней назад

There exists a vulnerability in SQLite versions before 3.50.2 where th ...

CVSS3: 9.8
github
19 дней назад

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.