[El-errata] ELSA-2026-7080 Important: Oracle Linux 10 nodejs22 security update
Errata Announcements for Oracle Linux
el-errata at oss.oracle.com
Tue Apr 14 04:56:02 UTC 2026
Oracle Linux Security Advisory ELSA-2026-7080
http://linux.oracle.com/errata/ELSA-2026-7080.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
nodejs-22.22.2-1.el10_1.x86_64.rpm
nodejs-devel-22.22.2-1.el10_1.x86_64.rpm
nodejs-docs-22.22.2-1.el10_1.noarch.rpm
nodejs-full-i18n-22.22.2-1.el10_1.x86_64.rpm
nodejs-libs-22.22.2-1.el10_1.x86_64.rpm
nodejs-npm-10.9.7-1.22.22.2.1.el10_1.x86_64.rpm
aarch64:
nodejs-22.22.2-1.el10_1.aarch64.rpm
nodejs-devel-22.22.2-1.el10_1.aarch64.rpm
nodejs-docs-22.22.2-1.el10_1.noarch.rpm
nodejs-full-i18n-22.22.2-1.el10_1.aarch64.rpm
nodejs-libs-22.22.2-1.el10_1.aarch64.rpm
nodejs-npm-10.9.7-1.22.22.2.1.el10_1.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/nodejs22-22.22.2-1.el10_1.src.rpm
Related CVEs:
CVE-2026-1525
CVE-2026-1526
CVE-2026-1528
CVE-2026-2229
CVE-2026-21710
CVE-2026-25547
CVE-2026-26996
CVE-2026-27135
CVE-2026-27904
Description of changes:
[1:22.22.2-1]
- Update to version 22.22.2
- introduced patch updating deps/nghttp2 to v 1.68.1 for CVE-2026-27135
- disabled failing tests in nghttp2 due to newer version
- patch for npm/braces CVE-2026-25547
[1:22.22.0-4]
- sources: changed ICU version syntax
More information about the El-errata
mailing list