RHSA-2024:1444: Important: nodejs:16 security update
Important: nodejs:16 security update
Other sources
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): nodejs: reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks (CVE-2024-22019) nodejs: HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/nodejsto a version that resolves this vulnerability.Fixed in 16.20.2-4.module+el8.9.0+21536+8fdee1fb - Upgrade
Upgrade
redhat/nodejs-nodemonto a version that resolves this vulnerability.Fixed in 3.0.1-1.module+el8.9.0+19741+03a9aaff - Upgrade
Upgrade
redhat/nodejs-packagingto a version that resolves this vulnerability.Fixed in 26-1.module+el8.9.0+19858+c237a2cf - Upgrade
Upgrade
redhat/nodejs-debuginfoto a version that resolves this vulnerability.Fixed in 16.20.2-4.module+el8.9.0+21536+8fdee1fb - Upgrade
Upgrade
redhat/nodejs-debugsourceto a version that resolves this vulnerability.Fixed in 16.20.2-4.module+el8.9.0+21536+8fdee1fb - Upgrade
Upgrade
redhat/nodejs-develto a version that resolves this vulnerability.Fixed in 16.20.2-4.module+el8.9.0+21536+8fdee1fb - Upgrade
Upgrade
redhat/nodejs-docsto a version that resolves this vulnerability.Fixed in 16.20.2-4.module+el8.9.0+21536+8fdee1fb - Upgrade
Upgrade
redhat/nodejs-full-i18nto a version that resolves this vulnerability.Fixed in 16.20.2-4.module+el8.9.0+21536+8fdee1fb - Upgrade
Upgrade
redhat/npmto a version that resolves this vulnerability.Fixed in 8.19.4-1.16.20.2.4.module+el8.9.0+21536+8fdee1fb - Upgrade
Upgrade
redhat/nodejsto a version that resolves this vulnerability.Fixed in 16.20.2-4.module+el8.9.0+21536+8fdee1fb.aa - Upgrade
Upgrade
redhat/nodejs-debuginfoto a version that resolves this vulnerability.Fixed in 16.20.2-4.module+el8.9.0+21536+8fdee1fb.aa - Upgrade
Upgrade
redhat/nodejs-debugsourceto a version that resolves this vulnerability.Fixed in 16.20.2-4.module+el8.9.0+21536+8fdee1fb.aa - Upgrade
Upgrade
redhat/nodejs-develto a version that resolves this vulnerability.Fixed in 16.20.2-4.module+el8.9.0+21536+8fdee1fb.aa - Upgrade
Upgrade
redhat/nodejs-full-i18nto a version that resolves this vulnerability.Fixed in 16.20.2-4.module+el8.9.0+21536+8fdee1fb.aa - Upgrade
Upgrade
redhat/npmto a version that resolves this vulnerability.Fixed in 8.19.4-1.16.20.2.4.module+el8.9.0+21536+8fdee1fb.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1444?
The severity of RHSA-2024:1444 is classified as important due to the potential for denial-of-service attacks.
How do I fix RHSA-2024:1444?
To fix RHSA-2024:1444, update your system to the latest available version of nodejs, specifically to 16.20.2-4.module+el8.9.0+21536+8fdee1fb.
What software is affected by RHSA-2024:1444?
RHSA-2024:1444 affects various versions of Red Hat Enterprise Linux, including x86_64, ARM 64, Power, and IBM z Systems.
What vulnerability does RHSA-2024:1444 address?
RHSA-2024:1444 addresses a vulnerability that involves reading unprocessed HTTP requests with unbounded chunk extensions, leading to potential denial of service.
What packages are updated in RHSA-2024:1444?
The packages updated in RHSA-2024:1444 include nodejs, nodejs-nodemon, nodejs-packaging, and others relevant to the Node.js ecosystem.