VDB
BDU%3A2025-02664
BDU%3A2025-02664
PUBLISHED
CVSS 5 MEDIUM
Уязвимость программной платформы Node.js, связанная с отсутствием освобождения памяти после эффективного срока службы, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Novell Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», ООО «РусБИТех-Астра», Node.js Foundation | Red Hat Enterprise Linux, openSUSE Tumbleweed, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), Astra Linux Special Edition (запись в едином реестре российских программ №369), SUSE Linux Enterprise Server for SAP Applications, SUSE Manager Server, SUSE Liberty Linux, SUSE Linux Enterprise High Performance Computing, Suse Linux Enterprise Server, OpenSUSE Leap, SUSE Linux Enterprise Module for Web Scripting, Node.js |
Timeline
- Mar 13, 2025 CVE Published
- Nov 26, 2025 CVE Updated
References
- https://redos.red-soft.ru/support/secure/ url
- https://security-tracker.debian.org/tracker/CVE-2025-23085 url
- https://access.redhat.com/security/cve/cve-2025-23085 url
- https://www.suse.com/security/cve/CVE-2025-23085.html url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2025-0923SE17 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-1020SE47 url
- https://wiki.astralinux.ru/astra-linux-se18-bulletin-2025-1113SE18 url
- https://nodejs.org/en/blog/vulnerability/january-2025-security-releases advisory
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory