Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-54530

Опубликовано: 14 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2026-54530: nodejs:22 security update (IMPORTANT)

nodejs [1:22.23.1-3]

  • deps: update npm/ip-address to 10.4.0
  • deps: update npm/brace-expansion to 2.1.4 Fix: CVE-2026-69192 & CVE-2026-54272 CVE-2026-69152

[1:22.23.1-3]

  • Backport patch: update sqlite to 3.53.4 Fix: CVE-2026-11824, CVE-2026-11822 Resolves: RHEL-224135 RHEL-224144

[1:22.23.1-2]

  • Backport patches for various CVEs Fixes: CVE-2026-59873 CVE-2026-59874 CVE-2026-13149 Resolves: RHEL-193842 RHEL-193874 RHEL-208661

[1:22.23.1-1]

  • Update to version 22.23.1 Resolves: RHEL-176170 Fixes: CVE-2026-12151 CVE-2026-48618 CVE-2026-48933 CVE-2026-48937 CVE-2026-48930 CVE-2026-48619 CVE-2026-48615 CVE-2026-48934 CVE-2026-48928 CVE-2026-48617 CVE-2026-48931 CVE-2026-48935 CVE-2026-42338

[1:22.22.2-1]

  • Update to version 22.22.2 Resolves: RHEL-154019 Fixes: CVE-2026-1528 CVE-2026-27135 CVE-2026-27904 CVE-2026-26996 CVE-2026-27135 CVE-2026-1528

[1:22.22.0-1]

  • Update to 22.22.0 Resolves: RHEL-118152

[1:22.19.0-1]

  • Update to 22.19.0 Resolves: RHEL-100424

[1:22.16.0-2]

  • Patch fix for sqlite CVE-2025-6965 Resolves: RHEL-103835

[1:22.16.0-1]

  • Update to 22.16.0 Fixes: CVE-2025-23166
  • Resolves: RHEL-91596 RHEL-92859

[1:22.15.0-1]

  • Update to 22.15.0
  • Drop upstream patches

nodejs-nodemon [3.1.14-2]

  • Rebase npm/brace-expansion to 5.0.9 Fixes: CVE-2026-69152 Resolves: RHEL-223760

[3.1.14-1]

  • Rebase to 3.1.14
  • Switch from using remys fork as a source to npm.
  • Resolves: RHEL-208659

[3.0.1-1]

  • Exclude ix86 arches from building. Related: RHEL-35991

[3.0.1-1]

  • Rebase to 3.0.1
  • Resolves: CVE-2022-25883

[2.0.20-2]

  • Patch bundled glob-parent
  • Resolves: CVE-2021-35065

[2.0.20-1]

  • Rebase to 2.0.20 Resolves: CVE-2022-3517

[2.0.15-1]

  • Resolves: RHBZ#2005419
  • Resolves CVE-2020-28469
  • Rebase to newest version
  • Change source to npmjs.com

[2.0.7-1]

  • Resolves: RHBZ#1953991
  • Update to 2.0.7 to resolve CVE-2020-28469

[2.0.3-1]

  • Updated

[1.18.3-1]

  • Resolves: #1615413
  • Updated
  • bundled

nodejs-packaging [2021.06-4]

  • Exclude ix86 arches from building. Related: RHEL-35991

[2021.06-4]

  • NPM bundler: also find namespaced bundled dependencies

[2021.06-3]

[2021.06-2]

  • Fix hard-coded output directory in the bundler

[2021.06-1]

  • Update to 2021.06-1
  • bundler: Handle archaic license metadata
  • bundler: Warn about bundled dependencies with no license metadata

[2021.01-3]

[2021.01-2]

  • nodejs-packaging-bundler improvements to handle uncommon characters

[2021.01]

  • Add nodejs-packaging-bundler and update README.md

[2020.09-1]

  • Move to dist-git as the upstream

[25-1]

  • Fix incorrect bundled library detection for Requires

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module nodejs:22 is enabled

nodejs

22.23.1-3.module+el8.10.0+90989+141244df

nodejs-devel

22.23.1-3.module+el8.10.0+90989+141244df

nodejs-docs

22.23.1-3.module+el8.10.0+90989+141244df

nodejs-full-i18n

22.23.1-3.module+el8.10.0+90989+141244df

nodejs-libs

22.23.1-3.module+el8.10.0+90989+141244df

nodejs-nodemon

3.1.14-2.module+el8.10.0+90989+141244df

nodejs-packaging

2021.06-4.module+el8.10.0+90968+e271b286

nodejs-packaging-bundler

2021.06-4.module+el8.10.0+90968+e271b286

npm

10.9.8-1.22.23.1.3.module+el8.10.0+90989+141244df

v8-12.4-devel

12.4.254.21-1.22.23.1.3.module+el8.10.0+90989+141244df

Oracle Linux x86_64

Module nodejs:22 is enabled

nodejs

22.23.1-3.module+el8.10.0+90989+141244df

nodejs-devel

22.23.1-3.module+el8.10.0+90989+141244df

nodejs-docs

22.23.1-3.module+el8.10.0+90989+141244df

nodejs-full-i18n

22.23.1-3.module+el8.10.0+90989+141244df

nodejs-libs

22.23.1-3.module+el8.10.0+90989+141244df

nodejs-nodemon

3.1.14-2.module+el8.10.0+90989+141244df

nodejs-packaging

2021.06-4.module+el8.10.0+90968+e271b286

nodejs-packaging-bundler

2021.06-4.module+el8.10.0+90968+e271b286

npm

10.9.8-1.22.23.1.3.module+el8.10.0+90989+141244df

v8-12.4-devel

12.4.254.21-1.22.23.1.3.module+el8.10.0+90989+141244df

Связанные уязвимости

rocky
6 дней назад

Important: nodejs:22 security update

rocky
6 дней назад

Important: nodejs:22 security update

oracle-oval
14 дней назад

ELSA-2026-55601: nodejs:22 security update (IMPORTANT)

rocky
6 дней назад

Important: nodejs:24 security update

rocky
6 дней назад

Important: nodejs:24 security update