VDB
GCVE-110-MAGEIA-2024-46
GCVE-110-MAGEIA-2024-46
Advisory Published
This is a security release. The following CVEs are fixed in this
release:
CVE-2024-21892 - Code injection and privilege escalation through Linux
capabilities- (High)
CVE-2024-22019 - http: Reading unprocessed HTTP request with unbounded
chunk extension allows DoS attacks- (High)
CVE-2023-46809 - Node.js is vulnerable to the Marvin Attack (timing
variant of the Bleichenbacher attack against PKCS#1 v1.5 padding) -
(Medium)
CVE-2024-22025 - Denial of Service by resource exhaustion in fetch()
brotli decoding - (Medium)
More detailed information on each of the vulnerabilities can be found in
february 2024 Security Releases blog post.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | homebank | 0 (affected), 5.7.2-1.mga9 (unaffected) | — |
| Mageia | yarnpkg | 0 (affected), 1.22.21-0.10.2.4.1.mga9 (unaffected), 0 (affected), 1.22.21-0.10.2.4.1.mga9 (unaffected) | — |
| Mageia | nodejs | 0 (affected), 18.19.1-1.mga9 (unaffected), 0 (affected), 18.19.1-1.mga9 (unaffected) | — |
Aliases
References
Browse GCVE Records
74,496 records in the GCVE database · Updated July 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.