Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-23085

Опубликовано: 21 янв. 2025
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential denial of service under certain conditions. This vulnerability affects HTTP/2 Server users on Node.js v18.x, v20.x, v22.x and v23.x.

A vulnerability was found in NodeJS when handling HTTP/2 connections, where the remote peer abruptly closes the socket without sending the proper HTTP/2 notification to the server, leading to a memory leak. This flaw allows an attacker to force the targeted process in the targeted host to an uncontrollable resource consumption state, starving the process and possibly other processes running at the same host to memory starvation, leading to a denial of service.

Меры по смягчению последствий

There's no available mitigation for this issue other than updating to the package version which contains the fix.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10nodejs22Affected
Red Hat Enterprise Linux 8nodejsFixedRHSA-2025:135112.02.2025
Red Hat Enterprise Linux 8nodejsFixedRHSA-2025:158217.02.2025
Red Hat Enterprise Linux 8nodejsFixedRHSA-2025:161117.02.2025
Red Hat Enterprise Linux 9nodejsFixedRHSA-2025:144313.02.2025
Red Hat Enterprise Linux 9nodejsFixedRHSA-2025:144613.02.2025
Red Hat Enterprise Linux 9nodejsFixedRHSA-2025:161317.02.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2342618nodejs: GOAWAY HTTP/2 frames cause memory leak outside heap

EPSS

Процентиль: 26%
0.00086
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential denial of service under certain conditions. This vulnerability affects HTTP/2 Server users on Node.js v18.x, v20.x, v22.x and v23.x.

CVSS3: 5.3
nvd
4 месяца назад

A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential denial of service under certain conditions. This vulnerability affects HTTP/2 Server users on Node.js v18.x, v20.x, v22.x and v23.x.

CVSS3: 5.3
msrc
4 месяца назад

Описание отсутствует

CVSS3: 5.3
debian
4 месяца назад

A memory leak could occur when a remote peer abruptly closes the socke ...

CVSS3: 5.3
github
4 месяца назад

A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential denial of service under certain conditions. This vulnerability affects HTTP/2 Server users on Node.js v18.x, v20.x, v22.x and v23.x.

EPSS

Процентиль: 26%
0.00086
Низкий

5.3 Medium

CVSS3