Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gfv8-jx4x-32h7

Опубликовано: 30 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whether the provided socket descriptor fits in select(2)'s file descriptor set size limit of FD_SETSIZE (1024).

An attacker who is able to force a libnv application to allocate large file descriptors, e.g., by opening many descriptors and executing a program which is not careful to close them upon startup, can trigger stack corruption. If the target application is setuid-root, then this could be used to elevate local privileges.

When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whether the provided socket descriptor fits in select(2)'s file descriptor set size limit of FD_SETSIZE (1024).

An attacker who is able to force a libnv application to allocate large file descriptors, e.g., by opening many descriptors and executing a program which is not careful to close them upon startup, can trigger stack corruption. If the target application is setuid-root, then this could be used to elevate local privileges.

EPSS

Процентиль: 5%
0.00151
Низкий

7.8 High

CVSS3

Дефекты

CWE-121

Связанные уязвимости

CVSS3: 7.8
nvd
5 месяцев назад

When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whether the provided socket descriptor fits in select(2)'s file descriptor set size limit of FD_SETSIZE (1024). An attacker who is able to force a libnv application to allocate large file descriptors, e.g., by opening many descriptors and executing a program which is not careful to close them upon startup, can trigger stack corruption. If the target application is setuid-root, then this could be used to elevate local privileges.

CVSS3: 7.8
fstec
5 месяцев назад

Уязвимость компонента File Descriptor Handler ядра операционных систем FreeBSD, позволяющая нарушителю выполнить произвольный код с привилегиями root

EPSS

Процентиль: 5%
0.00151
Низкий

7.8 High

CVSS3

Дефекты

CWE-121