First published: Mon May 05 2025(Updated: )
Moderate: nodejs:20 security update
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Linux 8 | ||
Red Hat Enterprise Linux for Power, little endian - Extended Update Support | ||
Red Hat Enterprise Linux Server for IBM z Systems | ||
Red Hat Enterprise Linux for ARM 64 | ||
redhat/nodejs | <20.19.1-1.module+el8.10.0+23054+5431297f | 20.19.1-1.module+el8.10.0+23054+5431297f |
redhat/nodejs-nodemon | <3.0.1-1.module+el8.10.0+22904+d0fedeff | 3.0.1-1.module+el8.10.0+22904+d0fedeff |
redhat/nodejs-packaging | <2021.06-4.module+el8.10.0+22904+d0fedeff | 2021.06-4.module+el8.10.0+22904+d0fedeff |
redhat/nodejs-docs | <20.19.1-1.module+el8.10.0+23054+5431297f | 20.19.1-1.module+el8.10.0+23054+5431297f |
redhat/nodejs-nodemon | <3.0.1-1.module+el8.10.0+22904+d0fedeff | 3.0.1-1.module+el8.10.0+22904+d0fedeff |
redhat/nodejs-packaging | <2021.06-4.module+el8.10.0+22904+d0fedeff | 2021.06-4.module+el8.10.0+22904+d0fedeff |
redhat/nodejs-packaging-bundler | <2021.06-4.module+el8.10.0+22904+d0fedeff | 2021.06-4.module+el8.10.0+22904+d0fedeff |
redhat/nodejs | <20.19.1-1.module+el8.10.0+23054+5431297f | 20.19.1-1.module+el8.10.0+23054+5431297f |
redhat/nodejs-debuginfo | <20.19.1-1.module+el8.10.0+23054+5431297f | 20.19.1-1.module+el8.10.0+23054+5431297f |
redhat/nodejs-debugsource | <20.19.1-1.module+el8.10.0+23054+5431297f | 20.19.1-1.module+el8.10.0+23054+5431297f |
redhat/nodejs-devel | <20.19.1-1.module+el8.10.0+23054+5431297f | 20.19.1-1.module+el8.10.0+23054+5431297f |
redhat/nodejs-full-i18n | <20.19.1-1.module+el8.10.0+23054+5431297f | 20.19.1-1.module+el8.10.0+23054+5431297f |
redhat/npm | <10.8.2-1.20.19.1.1.module+el8.10.0+23054+5431297f | 10.8.2-1.20.19.1.1.module+el8.10.0+23054+5431297f |
redhat/nodejs-debuginfo | <20.19.1-1.module+el8.10.0+23054+5431297f | 20.19.1-1.module+el8.10.0+23054+5431297f |
redhat/nodejs-debugsource | <20.19.1-1.module+el8.10.0+23054+5431297f | 20.19.1-1.module+el8.10.0+23054+5431297f |
redhat/nodejs-devel | <20.19.1-1.module+el8.10.0+23054+5431297f | 20.19.1-1.module+el8.10.0+23054+5431297f |
redhat/nodejs-full-i18n | <20.19.1-1.module+el8.10.0+23054+5431297f | 20.19.1-1.module+el8.10.0+23054+5431297f |
redhat/npm | <10.8.2-1.20.19.1.1.module+el8.10.0+23054+5431297f | 10.8.2-1.20.19.1.1.module+el8.10.0+23054+5431297f |
redhat/nodejs | <20.19.1-1.module+el8.10.0+23054+5431297f | 20.19.1-1.module+el8.10.0+23054+5431297f |
redhat/nodejs-debuginfo | <20.19.1-1.module+el8.10.0+23054+5431297f | 20.19.1-1.module+el8.10.0+23054+5431297f |
redhat/nodejs-debugsource | <20.19.1-1.module+el8.10.0+23054+5431297f | 20.19.1-1.module+el8.10.0+23054+5431297f |
redhat/nodejs-devel | <20.19.1-1.module+el8.10.0+23054+5431297f | 20.19.1-1.module+el8.10.0+23054+5431297f |
redhat/nodejs-full-i18n | <20.19.1-1.module+el8.10.0+23054+5431297f | 20.19.1-1.module+el8.10.0+23054+5431297f |
redhat/npm | <10.8.2-1.20.19.1.1.module+el8.10.0+23054+5431297f | 10.8.2-1.20.19.1.1.module+el8.10.0+23054+5431297f |
redhat/nodejs | <20.19.1-1.module+el8.10.0+23054+5431297f.aa | 20.19.1-1.module+el8.10.0+23054+5431297f.aa |
redhat/nodejs-debuginfo | <20.19.1-1.module+el8.10.0+23054+5431297f.aa | 20.19.1-1.module+el8.10.0+23054+5431297f.aa |
redhat/nodejs-debugsource | <20.19.1-1.module+el8.10.0+23054+5431297f.aa | 20.19.1-1.module+el8.10.0+23054+5431297f.aa |
redhat/nodejs-devel | <20.19.1-1.module+el8.10.0+23054+5431297f.aa | 20.19.1-1.module+el8.10.0+23054+5431297f.aa |
redhat/nodejs-full-i18n | <20.19.1-1.module+el8.10.0+23054+5431297f.aa | 20.19.1-1.module+el8.10.0+23054+5431297f.aa |
redhat/npm | <10.8.2-1.20.19.1.1.module+el8.10.0+23054+5431297f.aa | 10.8.2-1.20.19.1.1.module+el8.10.0+23054+5431297f.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2025:4461 is classified as moderate.
To fix RHSA-2025:4461, update the affected packages to their remedial versions specified in the advisory.
Affected packages in RHSA-2025:4461 include nodejs, nodejs-nodemon, and nodejs-packaging among others.
RHSA-2025:4461 addresses a use-after-free vulnerability in c-ares as identified by CVE-2025-31498.
The recommended package version for nodejs is 20.19.1-1.module+el8.10.0+23054+5431297f.