Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.GENTOO.ANNOUNCE
  • [gentoo-announce] [ GLSA 202505-11 ] Node.js: Multiple Vulnerabilities

    From [email protected]@21:1/5 to All on Wed May 14 16:50:02 2025
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Gentoo Linux Security Advisory GLSA 202505-11
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    https://security.gentoo.org/
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: High
    Title: Node.js: Multiple Vulnerabilities
    Date: May 14, 2025
    Bugs: #916513, #924704, #928532, #936204
    ID: 202505-11

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Synopsis
    ========

    Multiple vulnerabilities have been discovered in Node.js, the worst of
    which could lead to execution of arbitrary code.

    Background
    ==========

    Node.js is a JavaScript runtime built on Chrome’s V8 JavaScript engine.

    Affected packages
    =================

    Package Vulnerable Unaffected
    --------------- ------------ ------------
    net-libs/nodejs < 22.4.1 >= 22.4.1

    Description
    ===========

    Multiple vulnerabilities have been discovered in Node.js. Please review
    the CVE identifiers referenced below for details.

    Impact
    ======

    Please review the referenced CVE identifiers for details.

    Workaround
    ==========

    There is no known workaround at this time.

    Resolution
    ==========

    All Node.js users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=net-libs/nodejs-22.4.1"

    References
    ==========

    [ 1 ] CVE-2023-38552
    https://nvd.nist.gov/vuln/detail/CVE-2023-38552
    [ 2 ] CVE-2023-39331
    https://nvd.nist.gov/vuln/detail/CVE-2023-39331
    [ 3 ] CVE-2023-39332
    https://nvd.nist.gov/vuln/detail/CVE-2023-39332
    [ 4 ] CVE-2023-39333
    https://nvd.nist.gov/vuln/detail/CVE-2023-39333
    [ 5 ] CVE-2023-44487
    https://nvd.nist.gov/vuln/detail/CVE-2023-44487
    [ 6 ] CVE-2023-45143
    https://nvd.nist.gov/vuln/detail/CVE-2023-45143
    [ 7 ] CVE-2023-46809
    https://nvd.nist.gov/vuln/detail/CVE-2023-46809
    [ 8 ] CVE-2024-21890
    https://nvd.nist.gov/vuln/detail/CVE-2024-21890
    [ 9 ] CVE-2024-21891
    https://nvd.nist.gov/vuln/detail/CVE-2024-21891
    [ 10 ] CVE-2024-21892
    https://nvd.nist.gov/vuln/detail/CVE-2024-21892
    [ 11 ] CVE-2024-21896
    https://nvd.nist.gov/vuln/detail/CVE-2024-21896
    [ 12 ] CVE-2024-22017
    https://nvd.nist.gov/vuln/detail/CVE-2024-22017
    [ 13 ] CVE-2024-22018
    https://nvd.nist.gov/vuln/detail/CVE-2024-22018
    [ 14 ] CVE-2024-22019
    https://nvd.nist.gov/vuln/detail/CVE-2024-22019
    [ 15 ] CVE-2024-22020
    https://nvd.nist.gov/vuln/detail/CVE-2024-22020
    [ 16 ] CVE-2024-22025
    https://nvd.nist.gov/vuln/detail/CVE-2024-22025
    [ 17 ] CVE-2024-27982
    https://nvd.nist.gov/vuln/detail/CVE-2024-27982
    [ 18 ] CVE-2024-27983
    https://nvd.nist.gov/vuln/detail/CVE-2024-27983
    [ 19 ] CVE-2024-36137
    https://nvd.nist.gov/vuln/detail/CVE-2024-36137
    [ 20 ] CVE-2024-37372
    https://nvd.nist.gov/vuln/detail/CVE-2024-37372

    Availability
    ============

    This GLSA and any updates to it are available for viewing at
    the Gentoo Security Website:

    https://security.gentoo.org/glsa/202505-11

    Concerns?
    =========

    Security is a primary focus of Gentoo Linux and ensuring the
    confidentiality and security of our users' machines is of utmost
    importance to us. Any security concerns should be addressed to [email protected] or alternatively, you may file a bug at https://bugs.gentoo.org.

    License
    =======

    Copyright 2025 Gentoo Foundation, Inc; referenced text
    belongs to its owner(s).

    The contents of this document are licensed under the
    Creative Commons - Attribution / Share Alike license.

    https://creativecommons.org/licenses/by-sa/2.5
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmgkrEkACgkQFMQkOaVy +9kuZxAArMr57C24N9LqCCytMt3DT4aVtLd7gm5SQBcGKKP6iX8IzsjOXon7+r1W P79TTlef2AloMyQYtge1RcBplNyLzuY4sInjU7V2E3uHfyNOyQCf1Np14ALm5egb oj0+MluYBvHwAhYn1JU3CEqlbMJ1qSLxjjGdW6tSB7t0HVSGySbMNJmCDeraCvcN P23MLKjL+XVDWFERmiLMhhquWuJx5A3I8u4N7f768LPt5W8zAhWxRVeDZCpuuUpg XT5Cd9+NTKgiTLa5t4rL/6GS5H9HOHPFU0N0RJjzhex/FhYxzJ8ADj6nlmGwQGzL /bmd6Vdo3mpSU3LgAMRXkvTVfdwSDLjc/CeKfBYA8o74yljRHkM84VkuXKqFTkux WHwDYf0Io138jg6UIygaujOfwN1bcWqhj4hlQeGkq5BsezMJ2pgJ2XZ4ZjFGZqMB dp2/bB5atJISVrXfY4g8FDxXFFuk933WrGFNUD4YQUq9Ymdj/qd83UKBrppmzQAC PTF2c8co717GJtNd8+7NuEDCGWrjSpxRBpXjXafQIkL3Y9reWZVgLBF6N3fUkGd7 0IV90uXhHFfgM4lz43yfdmeRA3OhHZGcCrSvxbkTfbQdDA6KwoS1ArNe3kWBLfNZ XUzHexXkb0yAyE5wcnCqJBQi/9inwCFe+RHqLLHwVFzW7yEJSVE=
    =tpkF
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • Who's Online

  • Recent Visitors

    • Krenn
      Tue Jun 9 11:18:15 2026
      from Sydney, Nsw via Telnet
    • Bob Worm
      Tue Jun 9 10:31:07 2026
      from Wales, Uk via Telnet
    • Centurion
      Mon Jun 8 23:30:43 2026
      from Berea, Ohio via Telnet
    • Centurion
      Mon Jun 8 21:33:11 2026
      from Berea, Ohio via Telnet
    • Bob Worm
      Mon Jun 8 20:15:00 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 16:33:22 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 14:11:46 2026
      from Wales, Uk via Telnet
    • Krenn
      Mon Jun 8 11:22:02 2026
      from Sydney, Nsw via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 44:22:03
    Calls: 12,111
    Calls today: 2
    Files: 15,010
    Messages: 6,518,458

© >>> Magnum BBS <<<, 2026