RHSA-2024:1444: Important: nodejs:16 security update

Published Mar 20, 2024
·
Updated

Important: nodejs:16 security update

Other sources

Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): nodejs: reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks (CVE-2024-22019) nodejs: HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

— Red Hat

Affected Software

33 affected componentsFixes available
redhat/nodejs<16.20.2-4.module+el8.9.0+21536+8fdee1fb
16.20.2-4.module+el8.9.0+21536+8fdee1fb
redhat/nodejs-nodemon<3.0.1-1.module+el8.9.0+19741+03a9aaff
3.0.1-1.module+el8.9.0+19741+03a9aaff
redhat/nodejs-packaging<26-1.module+el8.9.0+19858+c237a2cf
26-1.module+el8.9.0+19858+c237a2cf
redhat/nodejs-docs<16.20.2-4.module+el8.9.0+21536+8fdee1fb
16.20.2-4.module+el8.9.0+21536+8fdee1fb
redhat/nodejs-nodemon<3.0.1-1.module+el8.9.0+19741+03a9aaff
3.0.1-1.module+el8.9.0+19741+03a9aaff
redhat/nodejs-packaging<26-1.module+el8.9.0+19858+c237a2cf
26-1.module+el8.9.0+19858+c237a2cf
redhat/nodejs<16.20.2-4.module+el8.9.0+21536+8fdee1fb
16.20.2-4.module+el8.9.0+21536+8fdee1fb
redhat/nodejs-debuginfo<16.20.2-4.module+el8.9.0+21536+8fdee1fb
16.20.2-4.module+el8.9.0+21536+8fdee1fb
redhat/nodejs-debugsource<16.20.2-4.module+el8.9.0+21536+8fdee1fb
16.20.2-4.module+el8.9.0+21536+8fdee1fb
redhat/nodejs-devel<16.20.2-4.module+el8.9.0+21536+8fdee1fb
16.20.2-4.module+el8.9.0+21536+8fdee1fb
redhat/nodejs-full-i18n<16.20.2-4.module+el8.9.0+21536+8fdee1fb
16.20.2-4.module+el8.9.0+21536+8fdee1fb
redhat/npm<8.19.4-1.16.20.2.4.module+el8.9.0+21536+8fdee1fb
8.19.4-1.16.20.2.4.module+el8.9.0+21536+8fdee1fb
redhat/nodejs-debuginfo<16.20.2-4.module+el8.9.0+21536+8fdee1fb
16.20.2-4.module+el8.9.0+21536+8fdee1fb
redhat/nodejs-debugsource<16.20.2-4.module+el8.9.0+21536+8fdee1fb
16.20.2-4.module+el8.9.0+21536+8fdee1fb
redhat/nodejs-devel<16.20.2-4.module+el8.9.0+21536+8fdee1fb
16.20.2-4.module+el8.9.0+21536+8fdee1fb
redhat/nodejs-full-i18n<16.20.2-4.module+el8.9.0+21536+8fdee1fb
16.20.2-4.module+el8.9.0+21536+8fdee1fb
redhat/npm<8.19.4-1.16.20.2.4.module+el8.9.0+21536+8fdee1fb
8.19.4-1.16.20.2.4.module+el8.9.0+21536+8fdee1fb
redhat/nodejs<16.20.2-4.module+el8.9.0+21536+8fdee1fb
16.20.2-4.module+el8.9.0+21536+8fdee1fb
redhat/nodejs-debuginfo<16.20.2-4.module+el8.9.0+21536+8fdee1fb
16.20.2-4.module+el8.9.0+21536+8fdee1fb
redhat/nodejs-debugsource<16.20.2-4.module+el8.9.0+21536+8fdee1fb
16.20.2-4.module+el8.9.0+21536+8fdee1fb
redhat/nodejs-devel<16.20.2-4.module+el8.9.0+21536+8fdee1fb
16.20.2-4.module+el8.9.0+21536+8fdee1fb
redhat/nodejs-full-i18n<16.20.2-4.module+el8.9.0+21536+8fdee1fb
16.20.2-4.module+el8.9.0+21536+8fdee1fb
redhat/npm<8.19.4-1.16.20.2.4.module+el8.9.0+21536+8fdee1fb
8.19.4-1.16.20.2.4.module+el8.9.0+21536+8fdee1fb
redhat/nodejs<16.20.2-4.module+el8.9.0+21536+8fdee1fb.aa
16.20.2-4.module+el8.9.0+21536+8fdee1fb.aa
redhat/nodejs-debuginfo<16.20.2-4.module+el8.9.0+21536+8fdee1fb.aa
16.20.2-4.module+el8.9.0+21536+8fdee1fb.aa
redhat/nodejs-debugsource<16.20.2-4.module+el8.9.0+21536+8fdee1fb.aa
16.20.2-4.module+el8.9.0+21536+8fdee1fb.aa
redhat/nodejs-devel<16.20.2-4.module+el8.9.0+21536+8fdee1fb.aa
16.20.2-4.module+el8.9.0+21536+8fdee1fb.aa
redhat/nodejs-full-i18n<16.20.2-4.module+el8.9.0+21536+8fdee1fb.aa
16.20.2-4.module+el8.9.0+21536+8fdee1fb.aa
redhat/npm<8.19.4-1.16.20.2.4.module+el8.9.0+21536+8fdee1fb.aa
8.19.4-1.16.20.2.4.module+el8.9.0+21536+8fdee1fb.aa
Red Hat Red Hat Enterprise Linux for x86_64
Red Hat Red Hat Enterprise Linux for ARM 64
Red Hat Red Hat Enterprise Linux for Power, little endian
Red Hat Red Hat Enterprise Linux for IBM z Systems

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/nodejs to a version that resolves this vulnerability.

    Fixed in 16.20.2-4.module+el8.9.0+21536+8fdee1fb
  2. Upgrade

    Upgrade redhat/nodejs-nodemon to a version that resolves this vulnerability.

    Fixed in 3.0.1-1.module+el8.9.0+19741+03a9aaff
  3. Upgrade

    Upgrade redhat/nodejs-packaging to a version that resolves this vulnerability.

    Fixed in 26-1.module+el8.9.0+19858+c237a2cf
  4. Upgrade

    Upgrade redhat/nodejs-debuginfo to a version that resolves this vulnerability.

    Fixed in 16.20.2-4.module+el8.9.0+21536+8fdee1fb
  5. Upgrade

    Upgrade redhat/nodejs-debugsource to a version that resolves this vulnerability.

    Fixed in 16.20.2-4.module+el8.9.0+21536+8fdee1fb
  6. Upgrade

    Upgrade redhat/nodejs-devel to a version that resolves this vulnerability.

    Fixed in 16.20.2-4.module+el8.9.0+21536+8fdee1fb
  7. Upgrade

    Upgrade redhat/nodejs-docs to a version that resolves this vulnerability.

    Fixed in 16.20.2-4.module+el8.9.0+21536+8fdee1fb
  8. Upgrade

    Upgrade redhat/nodejs-full-i18n to a version that resolves this vulnerability.

    Fixed in 16.20.2-4.module+el8.9.0+21536+8fdee1fb
  9. Upgrade

    Upgrade redhat/npm to a version that resolves this vulnerability.

    Fixed in 8.19.4-1.16.20.2.4.module+el8.9.0+21536+8fdee1fb
  10. Upgrade

    Upgrade redhat/nodejs to a version that resolves this vulnerability.

    Fixed in 16.20.2-4.module+el8.9.0+21536+8fdee1fb.aa
  11. Upgrade

    Upgrade redhat/nodejs-debuginfo to a version that resolves this vulnerability.

    Fixed in 16.20.2-4.module+el8.9.0+21536+8fdee1fb.aa
  12. Upgrade

    Upgrade redhat/nodejs-debugsource to a version that resolves this vulnerability.

    Fixed in 16.20.2-4.module+el8.9.0+21536+8fdee1fb.aa
  13. Upgrade

    Upgrade redhat/nodejs-devel to a version that resolves this vulnerability.

    Fixed in 16.20.2-4.module+el8.9.0+21536+8fdee1fb.aa
  14. Upgrade

    Upgrade redhat/nodejs-full-i18n to a version that resolves this vulnerability.

    Fixed in 16.20.2-4.module+el8.9.0+21536+8fdee1fb.aa
  15. Upgrade

    Upgrade redhat/npm to a version that resolves this vulnerability.

    Fixed in 8.19.4-1.16.20.2.4.module+el8.9.0+21536+8fdee1fb.aa

Event History

Mar 20, 2024
Advisory Published
via Red Hat·12:00 AM
Data Sourced
via Red Hat·12:00 AM
RemedyDescriptionAffected Software
Advisory Published
via Red Hat·04:27 PM

Frequently Asked Questions

1

What is the severity of RHSA-2024:1444?

The severity of RHSA-2024:1444 is classified as important due to the potential for denial-of-service attacks.

2

How do I fix RHSA-2024:1444?

To fix RHSA-2024:1444, update your system to the latest available version of nodejs, specifically to 16.20.2-4.module+el8.9.0+21536+8fdee1fb.

3

What software is affected by RHSA-2024:1444?

RHSA-2024:1444 affects various versions of Red Hat Enterprise Linux, including x86_64, ARM 64, Power, and IBM z Systems.

4

What vulnerability does RHSA-2024:1444 address?

RHSA-2024:1444 addresses a vulnerability that involves reading unprocessed HTTP requests with unbounded chunk extensions, leading to potential denial of service.

5

What packages are updated in RHSA-2024:1444?

The packages updated in RHSA-2024:1444 include nodejs, nodejs-nodemon, nodejs-packaging, and others relevant to the Node.js ecosystem.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203