RHSA-2025:8493: Important: nodejs22 security update
Important: nodejs22 security update
Other sources
Node.js is a platform built on Chrome's JavaScript runtime \ for easily building fast, scalable network applications. \ Node.js uses an event-driven, non-blocking I/O model that \ makes it lightweight and efficient, perfect for data-intensive \ real-time applications that run across distributed devices.<br>Security Fix(es):<br><li> nodejs: Remote Crash via SignTraits::DeriveBits() in Node.js (CVE-2025-23166)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:8493?
The severity of RHSA-2025:8493 is classified as important.
How do I fix RHSA-2025:8493?
To fix RHSA-2025:8493, update the affected Node.js packages to version 22.16.0-1.el10_0.
What are the affected software versions for RHSA-2025:8493?
RHSA-2025:8493 affects various versions of Red Hat Enterprise Linux and the Node.js 22 packages.
Is it safe to ignore the RHSA-2025:8493 update?
Ignoring the RHSA-2025:8493 update is not recommended as it may expose your systems to security vulnerabilities.
What should I do if I cannot update to the version specified in RHSA-2025:8493?
If unable to update to the specified version for RHSA-2025:8493, consider mitigating the risk by reviewing application configurations and access controls.