Issued at: 2025-02-13
Updated at: 2025-10-17
Synopsis
Moderate: nodejs:18 security update
Description
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.
Security Fix(es):
* undici: Undici Uses Insufficiently Random Values (CVE-2025-22150)
* nodejs: GOAWAY HTTP/2 frames cause memory leak outside heap (CVE-2025-23085)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected products
Rocky Linux 9.6 aarch64
Rocky Linux 9.6 ppc64le
Rocky Linux 9.6 s390x
Rocky Linux 9.6 x86_64
Fixes
2339176
2342618
CVEs
CVE-2025-22150
CVE-2025-23085
Affected packages
Rocky Linux 9.6 aarch64 - AppStream
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32494+726e9034.noarch.rpm
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32494+726e9034.src.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32494+726e9034.noarch.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32494+726e9034.src.rpm
nodejs-packaging-bundler-0:2021.06-4.module+el9.6.0+32494+726e9034.noarch.rpm
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32185+bd121a25.noarch.rpm
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32143+ae966e5b.noarch.rpm
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32143+ae966e5b.src.rpm
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32185+bd121a25.src.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32143+ae966e5b.noarch.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32185+bd121a25.noarch.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32143+ae966e5b.src.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32185+bd121a25.src.rpm
nodejs-packaging-bundler-0:2021.06-4.module+el9.6.0+32143+ae966e5b.noarch.rpm
nodejs-packaging-bundler-0:2021.06-4.module+el9.6.0+32185+bd121a25.noarch.rpm
Rocky Linux 9.6 ppc64le - AppStream
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32494+726e9034.noarch.rpm
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32494+726e9034.src.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32494+726e9034.noarch.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32494+726e9034.src.rpm
nodejs-packaging-bundler-0:2021.06-4.module+el9.6.0+32494+726e9034.noarch.rpm
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32143+ae966e5b.noarch.rpm
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32185+bd121a25.noarch.rpm
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32143+ae966e5b.src.rpm
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32185+bd121a25.src.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32143+ae966e5b.noarch.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32185+bd121a25.noarch.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32143+ae966e5b.src.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32185+bd121a25.src.rpm
nodejs-packaging-bundler-0:2021.06-4.module+el9.6.0+32185+bd121a25.noarch.rpm
nodejs-packaging-bundler-0:2021.06-4.module+el9.6.0+32143+ae966e5b.noarch.rpm
Rocky Linux 9.6 s390x - AppStream
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32494+726e9034.noarch.rpm
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32494+726e9034.src.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32494+726e9034.noarch.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32494+726e9034.src.rpm
nodejs-packaging-bundler-0:2021.06-4.module+el9.6.0+32494+726e9034.noarch.rpm
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32143+ae966e5b.noarch.rpm
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32185+bd121a25.noarch.rpm
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32143+ae966e5b.src.rpm
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32185+bd121a25.src.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32143+ae966e5b.noarch.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32185+bd121a25.noarch.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32143+ae966e5b.src.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32185+bd121a25.src.rpm
nodejs-packaging-bundler-0:2021.06-4.module+el9.6.0+32143+ae966e5b.noarch.rpm
nodejs-packaging-bundler-0:2021.06-4.module+el9.6.0+32185+bd121a25.noarch.rpm
Rocky Linux 9.6 x86_64 - AppStream
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32494+726e9034.noarch.rpm
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32494+726e9034.src.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32494+726e9034.noarch.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32494+726e9034.src.rpm
nodejs-packaging-bundler-0:2021.06-4.module+el9.6.0+32494+726e9034.noarch.rpm
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32143+ae966e5b.noarch.rpm
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32185+bd121a25.noarch.rpm
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32185+bd121a25.src.rpm
nodejs-nodemon-0:3.0.1-1.module+el9.6.0+32143+ae966e5b.src.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32143+ae966e5b.noarch.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32185+bd121a25.noarch.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32143+ae966e5b.src.rpm
nodejs-packaging-0:2021.06-4.module+el9.6.0+32185+bd121a25.src.rpm
nodejs-packaging-bundler-0:2021.06-4.module+el9.6.0+32143+ae966e5b.noarch.rpm
nodejs-packaging-bundler-0:2021.06-4.module+el9.6.0+32185+bd121a25.noarch.rpm