CVE-2021-22918

NameCVE-2021-22918
DescriptionNode.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe, with the latter holding a pointer to the end of the buffer. This can lead to information disclosures or crashes. This function can be triggered via uv_getaddrinfo().
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-4936-1
Debian Bugs990561

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libuv1 (PTS)buster1.24.1-1+deb10u1fixed
buster (security)1.24.1-1+deb10u2fixed
bullseye1.40.0-2fixed
bullseye (security)1.40.0-2+deb11u1fixed
bookworm1.44.2-1fixed
bookworm (security)1.44.2-1+deb12u1fixed
trixie1.48.0-1fixed
sid1.48.0-1.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libuv1sourcestretch(not affected)
libuv1sourcebuster1.24.1-1+deb10u1DSA-4936-1
libuv1source(unstable)1.40.0-2990561

Notes

[stretch] - libuv1 <not-affected> (Vulnerable code added later)
https://nodejs.org/en/blog/vulnerability/july-2021-security-releases/
https://github.com/nodejs/node/commit/d33aead28bcec32a2a450f884907a6d971631829

Search for package or bug name: Reporting problems