RHSA-2019:2925: Important: nodejs:10 security update
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.The following packages have been upgraded to a later upstream version: nodejs (10.16.3).Security Fix(es): HTTP/2: large amount of data requests leads to denial of service (CVE-2019-9511) HTTP/2: flood using PING frames results in unbounded memory growth (CVE-2019-9512) HTTP/2: flood using PRIORITY frames results in excessive resource consumption (CVE-2019-9513) HTTP/2: flood using HEADERS frames results in unbounded memory growth (CVE-2019-9514) HTTP/2: flood using SETTINGS frames results in unbounded memory growth (CVE-2019-9515) HTTP/2: 0-length headers lead to denial of service (CVE-2019-9516) HTTP/2: request for large response leads to denial of service (CVE-2019-9517) HTTP/2: flood using empty frames results in excessive resource consumption (CVE-2019-9518) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/nodejsto a version that resolves this vulnerability.Fixed in 10.16.3-2.module+el8.0.0+4214+49953fda - Upgrade
Upgrade
redhat/nodejs-nodemonto a version that resolves this vulnerability.Fixed in 1.18.3-1.module+el8+2632+6c5111ed - Upgrade
Upgrade
redhat/nodejs-packagingto a version that resolves this vulnerability.Fixed in 17-3.module+el8+2873+aa7dfd9a - Upgrade
Upgrade
redhat/nodejs-debuginfoto a version that resolves this vulnerability.Fixed in 10.16.3-2.module+el8.0.0+4214+49953fda - Upgrade
Upgrade
redhat/nodejs-debugsourceto a version that resolves this vulnerability.Fixed in 10.16.3-2.module+el8.0.0+4214+49953fda - Upgrade
Upgrade
redhat/nodejs-develto a version that resolves this vulnerability.Fixed in 10.16.3-2.module+el8.0.0+4214+49953fda - Upgrade
Upgrade
redhat/nodejs-devel-debuginfoto a version that resolves this vulnerability.Fixed in 10.16.3-2.module+el8.0.0+4214+49953fda - Upgrade
Upgrade
redhat/nodejs-docsto a version that resolves this vulnerability.Fixed in 10.16.3-2.module+el8.0.0+4214+49953fda - Upgrade
Upgrade
redhat/npmto a version that resolves this vulnerability.Fixed in 6.9.0-1.10.16.3.2.module+el8.0.0+4214+49953fda - Upgrade
Upgrade
redhat/nodejsto a version that resolves this vulnerability.Fixed in 10.16.3-2.module+el8.0.0+4214+49953fda.aa - Upgrade
Upgrade
redhat/nodejs-debuginfoto a version that resolves this vulnerability.Fixed in 10.16.3-2.module+el8.0.0+4214+49953fda.aa - Upgrade
Upgrade
redhat/nodejs-debugsourceto a version that resolves this vulnerability.Fixed in 10.16.3-2.module+el8.0.0+4214+49953fda.aa - Upgrade
Upgrade
redhat/nodejs-develto a version that resolves this vulnerability.Fixed in 10.16.3-2.module+el8.0.0+4214+49953fda.aa - Upgrade
Upgrade
redhat/npmto a version that resolves this vulnerability.Fixed in 6.9.0-1.10.16.3.2.module+el8.0.0+4214+49953fda.aa - Upgrade
Upgrade
nodejsto a version that resolves this vulnerability.Fixed in 10.16.3
Event History
Frequently Asked Questions
What security vulnerabilities are fixed in RHSA-2019:2925?
RHSA-2019:2925 addresses issues related to the HTTP/2 implementation in Node.js.
How do I update Node.js to fix RHSA-2019:2925?
You can update Node.js to version 10.16.3-2.module+el8.0.0+4214+49953fda to resolve the vulnerabilities.
What versions of Node.js are affected by RHSA-2019:2925?
The vulnerability affects various versions of Node.js below 10.16.3-2.module+el8.0.0+4214+49953fda.
Is there a recommended action for RHSA-2019:2925?
The recommended action is to upgrade to the fixed package version as soon as possible.
What is the impact of not addressing RHSA-2019:2925?
Failing to address RHSA-2019:2925 could result in vulnerabilities in your Node.js applications due to security flaws in HTTP/2.