The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:8468 https://access.redhat.com/errata/RHSA-2025:8468
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:8467 https://access.redhat.com/errata/RHSA-2025:8467
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:8493 https://access.redhat.com/errata/RHSA-2025:8493
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:8506 https://access.redhat.com/errata/RHSA-2025:8506
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:8514 https://access.redhat.com/errata/RHSA-2025:8514
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:8902 https://access.redhat.com/errata/RHSA-2025:8902