Описание
A flaw in Node.js HTTP/2 handling allows nghttp2_session_mem_send() to be called re-entrantly while nghttp2_session_mem_recv() is executing, resulting in a heap-use-after-free.
This vulnerability affects Node.js 26.x, 24.x, and 22.x.
A heap use-after-free vulnerability in the Node.js HTTP/2 component allows a remote attacker to crash the application, causing a denial of service. This is triggered by an unexpected re-entrant call to nghttp2_session_mem_send() while nghttp2_session_mem_recv() is still executing.
Отчет
A remote attacker can exploit an Important heap use-after-free vulnerability in Node.js HTTP/2 to crash applications. The flaw, caused by re-entrant memory operations, leads to a denial of service for Red Hat environments with HTTP/2 enabled.
Меры по смягчению последствий
Restrict network access to Node.js HTTP/2 listeners to trusted clients only. If HTTP/2 is not required, disable it to remove the vulnerable handler from the attack surface.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | nodejs22 | Affected | ||
| Red Hat Enterprise Linux 10 | nodejs24 | Affected | ||
| Red Hat Enterprise Linux 8 | nodejs:22/nodejs | Affected | ||
| Red Hat Enterprise Linux 8 | nodejs:24/nodejs | Affected | ||
| Red Hat Enterprise Linux 9 | nodejs:22/nodejs | Affected | ||
| Red Hat Enterprise Linux 9 | nodejs:24/nodejs | Affected | ||
| Red Hat Enterprise Linux 9 | nodejs:26/nodejs | Affected | ||
| Red Hat Hardened Images | nodejs20 | Not affected | ||
| Red Hat Hardened Images | nodejs22 | Not affected | ||
| Red Hat Hardened Images | nodejs24 | Not affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` ...
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
7.5 High
CVSS3