RHSA-2019:2925: Important: nodejs:10 security update
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.The following packages have been upgraded to a later upstream version: nodejs (10.16.3).Security Fix(es): HTTP/2: large amount of data requests leads to denial of service (CVE-2019-9511) HTTP/2: flood using PING frames results in unbounded memory growth (CVE-2019-9512) HTTP/2: flood using PRIORITY frames results in excessive resource consumption (CVE-2019-9513) HTTP/2: flood using HEADERS frames results in unbounded memory growth (CVE-2019-9514) HTTP/2: flood using SETTINGS frames results in unbounded memory growth (CVE-2019-9515) HTTP/2: 0-length headers lead to denial of service (CVE-2019-9516) HTTP/2: request for large response leads to denial of service (CVE-2019-9517) HTTP/2: flood using empty frames results in excessive resource consumption (CVE-2019-9518) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What security vulnerabilities are fixed in RHSA-2019:2925?
RHSA-2019:2925 addresses issues related to the HTTP/2 implementation in Node.js.
How do I update Node.js to fix RHSA-2019:2925?
You can update Node.js to version 10.16.3-2.module+el8.0.0+4214+49953fda to resolve the vulnerabilities.
What versions of Node.js are affected by RHSA-2019:2925?
The vulnerability affects various versions of Node.js below 10.16.3-2.module+el8.0.0+4214+49953fda.
Is there a recommended action for RHSA-2019:2925?
The recommended action is to upgrade to the fixed package version as soon as possible.
What is the impact of not addressing RHSA-2019:2925?
Failing to address RHSA-2019:2925 could result in vulnerabilities in your Node.js applications due to security flaws in HTTP/2.