PT-2025-18371 · Node.Js+3 · Node.Js+3

Published

2013-01-09

·

Updated

2025-08-29

·

CVE-2025-47153

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions libuv and Node.js versions prior to nodejs 20.19.0+dfsg-2 i386.deb
Description The issue arises from certain build processes for libuv and Node.js on 32-bit systems, where the off t size is inconsistent. This inconsistency occurs because the build process for the libuv dynamic library always uses FILE OFFSET BITS=64, while the nodejs build uses the global system default of 32. This leads to out-of-bounds access. It is noted that this is not a problem in the Node.js software itself, but rather in the build process for certain binary packages, such as those for Debian GNU/Linux.
Recommendations For versions prior to nodejs 20.19.0+dfsg-2 i386.deb, consider rebuilding the nodejs package with consistent FILE OFFSET BITS settings to prevent out-of-bounds access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2025-12472
CVE-2025-47153
DLA-4152-1
DSA-5991-1
ECHO-4BB3-068F-64A1

Affected Products

Astra Linux
Debian
Node.Js
Libuv