Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:62416: Important: nodejs:22 security update

  • What: Security update for nodejs:22
  • Impact: Red Hat Enterprise Linux 9.6 users need to apply the update
Read Full Article →

Errata des produits Red Hat RHSA-2026:62416 - Security Advisory Publié : 2026-09-02 Mis à jour : 2026-09-02 RHSA-2026:62416 - Security Advisory Aperçu général Paquets mis à jour Synopsis Important: nodejs:22 security update Type / Sévérité Security Advisory: Important Analyse des correctifs dans Red Hat Insights Identifiez et remédiez aux systèmes concernés par cette alerte. Voir les systèmes concernés Sujet An update for the nodejs:22 module is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data (CVE-2026-11822) sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 (CVE-2026-11824) brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257) ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification (CVE-2026-54272) nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw (CVE-2026-58043) brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation (CVE-2026-69152) ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass (CVE-2026-69192) nodejs: Node.js: Remote memory exhaustion via HTTP/2 retained header blocks (CVE-2026-56846) nodejs: Node.js: Heap-use-after-free in HTTP/2 handling can lead to denial of service (CVE-2026-56848) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Produits concernés Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x Correctifs BZ - 2487258 - CVE-2026-11822 sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data BZ - 2487269 - CVE-2026-11824 sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 BZ - 2506433 - CVE-2026-14257 brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function BZ - 2507593 - CVE-2026-54272 ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification BZ - 2509171 - CVE-2026-58043 nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw BZ - 2510722 - CVE-2026-69152 brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation BZ - 2510801 - CVE-2026-69192 ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass BZ - 2510856 - CVE-2026-56846 nodejs: Node.js: Remote memory exhaustion via HTTP/2 retained header blocks CVE CVE-2026-11822 CVE-2026-11824 CVE-2026-14257 CVE-2026-54272 CVE-2026-56846 CVE-2026-56848 CVE-2026-58043 CVE-2026-69152 CVE-2026-69192 Références https://access.redhat.com/security/updates/classification/#important Remarque: Il existe peut-être des versions plus récentes de ces paquets. Cliquer sur un nom de paquet pour obtenir plus de détails. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM nodejs-22.23.2-1.module+el9.6.0+24769+299a7e3a.src.rpm SHA-256: 1490794b731908182851cdaa9fa1fa1ac111b0c0f2e0185f1c6d64cb1ed2c095 nodejs-nodemon-3.1.14-2.module+el9.6.0+24789+4011c12f.src.rpm SHA-256: f341ffe70a70eb2966ac910e4fe5a52251f06c1b795a7e20195a1b13b088cad7 nodejs-packaging-2021.06-4.module+el9.6.0+23473+45664c2d.src.rpm SHA-256: f80d5764e65ddce60321160b49c179d073b24484ff9001f0a0d8640b19a6a1f6 x86_64 nodejs-docs-22.23.2-1.module+el9.6.0+24769+299a7e3a.noarch.rpm SHA-256: 39dfe4d21f7b3604c13e21ccfc044a35750733996b8317f2bb19752ceaf34efa nodejs-nodemon-3.1.14-2.module+el9.6.0+24789+4011c12f.noarch.rpm SHA-256: 2b400f386cf9ec1a6515836790fa9d59eb37268d90a582df7fd15fc6003d60eb nodejs-packaging-2021.06-4.module+el9.6.0+23473+45664c2d.noarch.rpm SHA-256: f2048b25d0a1015b6c4f5553abb46f485a3cadca951fa2ec4098aa79ba089b0a nodejs-packaging-bundler-2021.06-4.module+el9.6.0+23473+45664c2d.noarch.rpm SHA-256: 938cf443eaa98f3d077172bff5a136239b820fcc88f4f455d505f83973355b1f nodejs-22.23.2-1.module+el9.6.0+24769+299a7e3a.x86_64.rpm SHA-256: 6cf22617e14d5c81e25dbdde562f3348bbb6c2a5fca31e5109f0a80473f34c3b nodejs-debuginfo-22.23.2-1.module+el9.6.0+24769+299a7e3a.x86_64.rpm SHA-256: 9aecb883aa5f24de511f68c1f6016f3c05b474f5a8b2105f1d9e484259f158f5 nodejs-debugsource-22.23.2-1.module+el9.6.0+24769+299a7e3a.x86_64.rpm SHA-256: ee916f06677b228ade1c5a0159784085f191a8b058b259b80a7c7c51b2cbf05c nodejs-devel-22.23.2-1.module+el9.6.0+24769+299a7e3a.x86_64.rpm SHA-256: 05a3cb074fd0ce524988d165012522b6099be40f12344208a9605494289d8d37 nodejs-docs-22.23.2-1.module+el9.6.0+24769+299a7e3a.noarch.rpm SHA-256: 39dfe4d21f7b3604c13e21ccfc044a35750733996b8317f2bb19752ceaf34efa nodejs-full-i18n-22.23.2-1.module+el9.6.0+24769+299a7e3a.x86_64.rpm SHA-256: 9b0717cfb651aaf8af6227a65f60b7adb477d98681f19c690edb1dbee020fc8f nodejs-libs-22.23.2-1.module+el9.6.0+24769+299a7e3a.x86_64.rpm SHA-256: bae1cb930ce8a2b2a2b96d1502d3b6eda02265f0c06ced1945f7cc876c47b6f9 nodejs-libs-debuginfo-22.23.2-1.module+el9.6.0+24769+299a7e3a.x86_64.rpm SHA-256: 93898b726d71cf0fd4d1dd8543a54d32f340d976e45dc8b9bb2cece8894b3a2e nodejs-nodemon-3.1.14-2.module+el9.6.0+24789+4011c12f.noarch.rpm SHA-256: 2b400f386cf9ec1a6515836790fa9d59eb37268d90a582df7fd15fc6003d60eb nodejs-packaging-2021.06-4.module+el9.6.0+23473+45664c2d.noarch.rpm SHA-256: f2048b25d0a1015b6c4f5553abb46f485a3cadca951fa2ec4098aa79ba089b0a nodejs-packaging-bundler-2021.06-4.module+el9.6.0+23473+45664c2d.noarch.rpm SHA-256: 938cf443eaa98f3d077172bff5a136239b820fcc88f4f455d505f83973355b1f npm-10.9.8-1.22.23.2.1.module+el9.6.0+24769+299a7e3a.x86_64.rpm SHA-256: 6978f74dd419647b3dc7678aaed5062772be1dd87e8a9a48e6f7e4849a23ca8d v8-12.4-devel-12.4.254.21-1.22.23.2.1.module+el9.6.0+24769+299a7e3a.x86_64.rpm SHA-256: 3d5177a80790e057383a61e7bf9a8f7379cc67aa5917e55d2a8e7a2e31626b44 nodejs-docs-22.23.2-1.module+el9.6.0+24769+299a7e3a.noarch.rpm SHA-256: 39dfe4d21f7b3604c13e21ccfc044a35750733996b8317f2bb19752ceaf34efa nodejs-nodemon-3.1.14-2.module+el9.6.0+24789+4011c12f.noarch.rpm SHA-256: 2b400f386cf9ec1a6515836790fa9d59eb37268d90a582df7fd15fc6003d60eb nodejs-packaging-2021.06-4.module+el9.6.0+23473+45664c2d.noarch.rpm SHA-256: f2048b25d0a1015b6c4f5553abb46f485a3cadca951fa2ec4098aa79ba089b0a nodejs-packaging-bundler-2021.06-4.module+el9.6.0+23473+45664c2d.noarch.rpm SHA-256: 938cf443eaa98f3d077172bff5a136239b820fcc88f4f455d505f83973355b1f nodejs-docs-22.23.2-1.module+el9.6.0+24769+299a7e3a.noarch.rpm SHA-256: 39dfe4d21f7b3604c13e21ccfc044a35750733996b8317f2bb19752ceaf34efa nodejs-nodemon-3.1.14-2.module+el9.6.0+24789+4011c12f.noarch.rpm SHA-256: 2b400f386cf9ec1a6515836790fa9d59eb37268d90a582df7fd15fc6003d60eb nodejs-packaging-2021.06-4.module+el9.6.0+23473+45664c2d.noarch.rpm SHA-256: f2048b25d0a1015b6c4f5553abb46f485a3cadca951fa2ec4098aa79ba089b0a nodejs-packaging-bundler-2021.06-4.module+el9.6.0+23473+45664c2d.noarch.rpm SHA-256: 938cf443eaa98f3d077172bff5a136239b820fcc88f4f455d505f83973355b1f Red Hat Enterprise Linux Server - AUS 9.6 SRPM nodejs-22.23.2-1.module+el9.6.0+24769+299a7e3a.src.rpm SHA-256: 1490794b731908182851cdaa9fa1fa1ac111b0c0f2e0185f1c6d64cb1ed2c095 nodejs-nodemon-3.1.14-2.module+el9.6.0+24789+4011c12f.src.rpm SHA-256: f341ffe70a70eb2966ac910e4fe5a52251f06c1b795a7e20195a1b13b088cad7 nodejs-packaging-2021.06-4.module+el9.6.0+23473+45664c2d.src.rpm SHA-256: f80d5764e65ddce60321160b49c179d073b24484ff9001f0a0d8640b19a6a1f6 x86_64 nodejs-docs-22.23.2-1.module+el9.6.0+24769+299a7e3a.noarch.rpm SHA-256: 39dfe4d21f7b3604c13e21ccfc044a35750733996b8317f2bb19752ceaf34efa nodejs-nodemon-3.1.14-2.module+el9.6.0+24789+4011c12f.noarch.rpm SHA-256: 2b400f386cf9ec1a6515836790fa9d59eb37268d90a582df7fd15fc6003d60eb nodejs-packaging-2021.06-4.module+el9.6.0+23473+45664c2d.noarch.rpm SHA-256: f2048b25d0a1015b6c4f5553abb46f485a3cadca951fa2ec4098aa79ba089b0a nodejs-packaging-bundler-2021.06-4.module+el9.6.0+23473+45664c2d.noarch.rpm SHA-256: 938cf443eaa98f3d077172bff5a136239b820fcc88f4f455d505f83973355b1f nodejs-22.23.2-1.module+el9.6.0+24769+299a7e3a.x86_64.rpm SHA-256: 6cf22617e14d5c81e25dbdde562f3348bbb6c2a5fca31e5109f0a80473f34c3b nodejs-debuginfo-22.23.2-1.module+el9.6.0+24769+299a7e3a.x86_64.rpm SHA-256: 9aecb883aa5f24de511f68c1f6016f3c05b474f5a8b2105f1d9e484259f158f5 nodejs-debugsourc

Share this article