Wind River Support Network

HomeDefectsLIN1024-6591
Fixed

LIN1024-6591 : Security Advisory - nodejs - CVE-2025-23085

Created: Jan 21, 2025    Updated: Jun 8, 2025
Resolved Date: Jun 5, 2025
Found In Version: 10.24.33.1
Fix Version: 10.24.33.10
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Userspace

Description

A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential denial of service under certain conditions.

This vulnerability affects HTTP/2 Server users on Node.js v18.x, v20.x, v22.x and v23.x.

https://nvd.nist.gov/vuln/detail/CVE-2025-23085

CVEs


Live chat
Online