跳转到帖子

Rocky Linux: CVE-2025-23085: nodejs-18 (Multiple Advisories)

recommended_posts

发布于
  • Members

Rocky Linux: CVE-2025-23085: nodejs-18 (Multiple Advisories)

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
02/07/2025
Created
02/15/2025
Added
02/14/2025
Modified
02/14/2025

Description

A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential denial of service under certain conditions. This vulnerability affects HTTP/2 Server users on Node.js v18.x, v20.x, v22.x and v23.x.

Solution(s)

  • rocky-upgrade-nodejs
  • rocky-upgrade-nodejs-debuginfo
  • rocky-upgrade-nodejs-debugsource
  • rocky-upgrade-nodejs-devel
  • rocky-upgrade-nodejs-full-i18n
  • rocky-upgrade-npm

References

  • https://attackerkb.com/topics/cve-2025-23085
  • CVE - 2025-23085
  • https://errata.rockylinux.org/RLSA-2025:1351
  • https://errata.rockylinux.org/RLSA-2025:1443
  • https://errata.rockylinux.org/RLSA-2025:1446
  • 查看数 716
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…