CVE-2021-22918

NameCVE-2021-22918
DescriptionNode.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe, with the latter holding a pointer to the end of the buffer. This can lead to information disclosures or crashes. This function can be triggered via uv_getaddrinfo().
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)
ReferencesDSA-4936-1
Debian Bugs990561

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libuv1 (PTS)buster, buster (security)1.24.1-1+deb10u1fixed
bullseye1.40.0-2fixed
bookworm, sid1.44.2-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libuv1sourcestretch(not affected)
libuv1sourcebuster1.24.1-1+deb10u1DSA-4936-1
libuv1source(unstable)1.40.0-2990561

Notes

[stretch] - libuv1 <not-affected> (Vulnerable code added later)
https://nodejs.org/en/blog/vulnerability/july-2021-security-releases/
https://github.com/nodejs/node/commit/d33aead28bcec32a2a450f884907a6d971631829

Search for package or bug name: Reporting problems