PT-2020-5852 · Node.Js+8 · Node.Js+8

Published

2020-01-24

·

Updated

2024-12-16

·

CVE-2021-22883

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Node.js versions prior to 10.24.0 Node.js versions prior to 12.21.0 Node.js versions prior to 14.16.0 Node.js versions prior to 15.10.0
Description: The issue is related to the incorrect handling of a large number of connection attempts with an unknownProtocol. This can lead to a denial of service attack, causing a leak of file descriptors. If a file descriptor limit is configured on the system, the server becomes unable to accept new connections and is prevented from opening files. Without a file descriptor limit, this results in excessive memory usage, potentially causing the system to run out of memory.
Recommendations: For versions prior to 10.24.0, update to version 10.24.0 or later. For versions prior to 12.21.0, update to version 12.21.0 or later. For versions prior to 14.16.0, update to version 14.16.0 or later. For versions prior to 15.10.0, update to version 15.10.0 or later.

Exploit

Fix

DoS

Missing Release of Resource after Effective Lifetime

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:0734
ALSA-2021:0735
ALSA-2021:0744
ALT-PU-2020-1090
ALT-PU-2021-1397
ALT-PU-2021-1493
ALT-PU-2022-3073
BDU:2021-01896
BIT-NODE-2021-22883
BIT-NODE-MIN-2021-22883
CESA-2021_0734
CESA-2021_0735
CESA-2021_0744
CVE-2021-22883
DSA-4863-1
MGASA-2021-0092
OESA-2021-1114
OPENSUSE-SU-2021:0356-1
OPENSUSE-SU-2021:0357-1
OPENSUSE-SU-2021:0372-1
OPENSUSE-SU-2021_0356-1
OPENSUSE-SU-2021_0357-1
OPENSUSE-SU-2021_0372-1
OPENSUSE-SU-2024:11096-1
RHSA-2021:0734
RHSA-2021:0735
RHSA-2021:0738
RHSA-2021:0739
RHSA-2021:0740
RHSA-2021:0741
RHSA-2021:0744
RHSA-2021:0827
RHSA-2021:0830
RHSA-2021:0831
RHSA-2021_0734
RHSA-2021_0735
RHSA-2021_0744
RLSA-2021:0734
RLSA-2021:0735
RLSA-2021:0744
SUSE-SU-2021:0648-1
SUSE-SU-2021:0649-1
SUSE-SU-2021:0650-1
SUSE-SU-2021:0651-1
SUSE-SU-2021:0673-1
SUSE-SU-2021:0674-1
SUSE-SU-2021_0648-1
SUSE-SU-2021_0649-1
SUSE-SU-2021_0650-1
SUSE-SU-2021_0651-1
SUSE-SU-2021_0673-1
SUSE-SU-2021_0674-1
USN-6418-1

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Node.Js
Red Hat
Rocky Linux
Suse
Ubuntu