PT-2021-2037 · Node.Js+8 · Node.Js+8

Published

2020-01-24

·

Updated

2026-05-18

·

CVE-2020-8265

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions: Node.js versions prior to 10.23.1 Node.js versions prior to 12.20.1 Node.js versions prior to 14.15.4 Node.js versions prior to 15.5.1
Description: The issue is related to a use-after-free bug in the TLS implementation of Node.js. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as the first argument. If the DoWrite method does not return an error, this object is passed back to the caller as part of a StreamWriteResult structure. This may be exploited to corrupt memory, leading to a Denial of Service or potentially other exploits.
Recommendations: For Node.js versions prior to 10.23.1, update to version 10.23.1 or later. For Node.js versions prior to 12.20.1, update to version 12.20.1 or later. For Node.js versions prior to 14.15.4, update to version 14.15.4 or later. For Node.js versions prior to 15.5.1, update to version 15.5.1 or later.

Exploit

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:0548
ALSA-2021:0549
ALSA-2021:0551
ALT-PU-2020-1090
ALT-PU-2021-1226
ALT-PU-2021-1493
ALT-PU-2022-3073
BDU:2021-00883
BIT-NODE-2020-8265
BIT-NODE-MIN-2020-8265
CESA-2021_0548
CESA-2021_0549
CESA-2021_0551
CLEANSTART-2026-BD71263
CLEANSTART-2026-IS74202
CLEANSTART-2026-JR35772
CLEANSTART-2026-JY06700
CLEANSTART-2026-KN34553
CLEANSTART-2026-KZ45320
CLEANSTART-2026-LJ44720
CLEANSTART-2026-LN12820
CLEANSTART-2026-TX00223
CLEANSTART-2026-WI75198
CVE-2020-8265
DSA-4826-1
MGASA-2021-0069
OESA-2021-1058
OPENSUSE-SU-2021:0064-1
OPENSUSE-SU-2021:0065-1
OPENSUSE-SU-2021:0066-1
OPENSUSE-SU-2021:0082-1
OPENSUSE-SU-2021_0064-1
OPENSUSE-SU-2021_0065-1
OPENSUSE-SU-2021_0066-1
OPENSUSE-SU-2021_0082-1
OPENSUSE-SU-2024:11096-1
RHSA-2021:0421
RHSA-2021:0485
RHSA-2021:0521
RHSA-2021:0548
RHSA-2021:0549
RHSA-2021:0551
RHSA-2021_0548
RHSA-2021_0549
RHSA-2021_0551
RLSA-2021:0548
RLSA-2021:0549
RLSA-2021:0551
SUSE-SU-2021:0060-1
SUSE-SU-2021:0061-1
SUSE-SU-2021:0062-1
SUSE-SU-2021:0068-1
SUSE-SU-2021:0082-1
SUSE-SU-2021:0107-1
SUSE-SU-2021_0107-1
USN-6380-1

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Node.Js
Red Hat
Rocky Linux
Suse
Ubuntu