nodejs:22 security update

エラータID: AXSA:2025-10001:01

リリース日: 
2025/06/09 Monday - 18:42
題名: 
nodejs:22 security update
影響のあるチャネル: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.

Security Fix(es):

* nodejs: Remote Crash via SignTraits::DeriveBits() in Node.js (CVE-2025-23166)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2025-23166
The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.

Modularity name: "nodejs"
Stream name: "22"

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. nodejs-nodemon-3.0.1-1.module+el8+1882+28e751eb.src.rpm
    MD5: 0d2134d461392f2267da84de1aff6162
    SHA-256: fb5ba49878d2d01e3d6488d4e23f842c6ba61ce738759e36e3a442aca1214acd
    Size: 340.07 kB
  2. nodejs-packaging-2021.06-4.module+el8+1882+28e751eb.src.rpm
    MD5: 02572af9371ee4dd991346a664201f3a
    SHA-256: 98ec745323cfcadcc78a250a1dff2ce1c2e131b450540aff15b97f50e30cde92
    Size: 30.62 kB
  3. nodejs-22.16.0-1.module+el8+1882+28e751eb.src.rpm
    MD5: 9bb1f11500650c6ff1ce2bd699617540
    SHA-256: 0ed343c2091ef450c34fdf073cebe803743f7abba12e2a4093653b5b632f140b
    Size: 93.65 MB

Asianux Server 8 for x86_64
  1. nodejs-22.16.0-1.module+el8+1882+28e751eb.x86_64.rpm
    MD5: 9ce9476be1c7544146367cd0fd59fe85
    SHA-256: 542157791e2ccae34294cf0bd146252aedbd7802ff7bae63e995466504ccfc1f
    Size: 2.11 MB
  2. nodejs-debugsource-22.16.0-1.module+el8+1882+28e751eb.x86_64.rpm
    MD5: ad7a044bf2ddb4f117cb28a485f6e479
    SHA-256: e5656239046926e4515a4aa1198f5bb708f830ddca38d13f33c7ae895a362746
    Size: 19.98 MB
  3. nodejs-devel-22.16.0-1.module+el8+1882+28e751eb.x86_64.rpm
    MD5: 9ba074e76ae40d21eef230e6274c1843
    SHA-256: d5a0d160e727b529127a384f9cef0146909cc21d3e099d68b2f0a309ab82fb4b
    Size: 267.90 kB
  4. nodejs-docs-22.16.0-1.module+el8+1882+28e751eb.noarch.rpm
    MD5: 2dfec91c939a8df0abc149ad4488ec64
    SHA-256: dd46cfae10e419429510e975e42913401e95d70f97fd50e23a30cffd12f6336c
    Size: 11.40 MB
  5. nodejs-full-i18n-22.16.0-1.module+el8+1882+28e751eb.x86_64.rpm
    MD5: a171aa6fab9b9283d7ba062c673ec712
    SHA-256: 65a60bab8f7a30a3dea97efd2bb9383c9cfa987bafc40ffb0dd05b33fba62870
    Size: 8.32 MB
  6. nodejs-libs-22.16.0-1.module+el8+1882+28e751eb.x86_64.rpm
    MD5: c36e1f55af24c0014d5bb585c335e39a
    SHA-256: 009553366466ceb6b9e7ba1b472626c9c3c9cbb3fb3f6b46e4144acd266f1b31
    Size: 20.86 MB
  7. nodejs-nodemon-3.0.1-1.module+el8+1882+28e751eb.noarch.rpm
    MD5: a2dcac3640c15020b8fce5693a0d5e90
    SHA-256: 59f73e1468210c9b26366f115f1edbcd8c1a392a4aa1b883e324c73eb867092b
    Size: 281.67 kB
  8. nodejs-packaging-2021.06-4.module+el8+1882+28e751eb.noarch.rpm
    MD5: 0a28594b3882c759c25ab69091468b9c
    SHA-256: ebfbc51e335c6e1f292acd573adf70682aaec261715166ec0d69b79864be5d3b
    Size: 24.25 kB
  9. nodejs-packaging-bundler-2021.06-4.module+el8+1882+28e751eb.noarch.rpm
    MD5: c7ea5fd836911538ea984ba894c97b8c
    SHA-256: 9ad07e073d61353bea7550274fd25466c574aca06eb70412f2f953871a83223a
    Size: 13.87 kB
  10. npm-10.9.2-1.22.16.0.1.module+el8+1882+28e751eb.x86_64.rpm
    MD5: 4be5db0afe3d1f6a50384ba064af73f8
    SHA-256: 326d50144be306930746df15437c755ee24934e92796bf6b5a8f654fa5f88a60
    Size: 2.28 MB
  11. v8-12.4-devel-12.4.254.21-1.22.16.0.1.module+el8+1882+28e751eb.x86_64.rpm
    MD5: f924300bb23e45129f9f862319815fdc
    SHA-256: cd0cbbd410e9664bc53d291c0ec1ccd45b94b15a8ba51f048704edafd14dc154
    Size: 14.67 kB