nodejs: Out of bounds (OOB) write via UCS-2 encoding
Published Aug 21, 2018
8.1
HIGHCVSS 3.0
EPSS 8.03%
Description
In all versions of Node.js prior to 6.14.4, 8.11.4 and 10.9.0 when used with UCS-2 encoding (recognized by Node.js under the names `'ucs2'`, `'ucs-2'`, `'utf16le'` and `'utf-16le'`), `Buffer#write()` can be abused to write outside of the bounds of a single `Buffer`. Writes that start from the second-to-last position of a buffer cause a miscalculation of the maximum length of the input bytes to be written.
Affected products
-
- Version All versions of Node.js prior to 6.14.4, 8.11.4 and 10.9.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The Node.js Project | Node.js | n/a |
|
No data.
Red Hat OpenShift Application Runtimes Node.js 10
rhoar-nodejs-1:10.9.0-1.el7
Fixed · RHSA-2018:2553
Red Hat OpenShift Application Runtimes Node.js 8
rhoar-nodejs-1:8.11.4-2.el7
Fixed · RHSA-2018:2552
Red Hat OpenShift Container Platform 3.11
jenkins-2-plugins-0:3.11.1539805268-1.el7
Fixed · RHSA-2018:3537
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-nodejs6-nodejs-0:6.11.3-6.el6
Fixed · RHSA-2018:2944
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS
rh-nodejs6-nodejs-0:6.11.3-6.el6
Fixed · RHSA-2018:2944
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs6-nodejs-0:6.11.3-7.el7
Fixed · RHSA-2018:2944
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs8-nodejs-0:8.11.4-1.el7
Fixed · RHSA-2018:2949
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS
rh-nodejs6-nodejs-0:6.11.3-7.el7
Fixed · RHSA-2018:2944
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
rh-nodejs6-nodejs-0:6.11.3-7.el7
Fixed · RHSA-2018:2944
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
rh-nodejs8-nodejs-0:8.11.4-1.el7
Fixed · RHSA-2018:2949
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-nodejs6-nodejs-0:6.11.3-7.el7
Fixed · RHSA-2018:2944
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-nodejs8-nodejs-0:8.11.4-1.el7
Fixed · RHSA-2018:2949
Red Hat Enterprise Linux 8
nodejs:10/nodejs
Not affected
Red Hat Mobile Application Platform 4
nodejs
Will not fix
Red Hat OpenShift Container Platform 3.10
logging-auth-proxy
Not affected
Red Hat OpenShift Container Platform 3.10
logging-kibana
Not affected
Red Hat OpenShift Container Platform 3.11
logging-auth-proxy
Not affected
Red Hat OpenShift Container Platform 3.11
logging-kibana
Not affected
Red Hat OpenShift Container Platform 3.2
logging-auth-proxy
Not affected
Red Hat OpenShift Container Platform 3.2
logging-kibana
Not affected
Red Hat OpenShift Container Platform 3.3
logging-auth-proxy
Not affected
Red Hat OpenShift Container Platform 3.3
logging-kibana
Not affected
Red Hat OpenShift Container Platform 3.4
logging-auth-proxy
Not affected
Red Hat OpenShift Container Platform 3.4
logging-kibana
Not affected
Red Hat OpenShift Container Platform 3.5
logging-auth-proxy
Not affected
Red Hat OpenShift Container Platform 3.5
logging-kibana
Not affected
Red Hat OpenShift Container Platform 3.6
logging-auth-proxy
Not affected
Red Hat OpenShift Container Platform 3.6
logging-kibana
Not affected
Red Hat OpenShift Container Platform 3.7
logging-auth-proxy
Not affected
Red Hat OpenShift Container Platform 3.7
logging-kibana
Not affected
Red Hat OpenShift Container Platform 3.9
logging-auth-proxy
Not affected
Red Hat OpenShift Container Platform 3.9
logging-kibana
Not affected
Red Hat OpenShift Enterprise 3.0
logging-auth-proxy
Not affected
Red Hat OpenShift Enterprise 3.0
logging-kibana
Not affected
Red Hat OpenShift Enterprise 3.1
logging-auth-proxy
Not affected
Red Hat OpenShift Enterprise 3.1
logging-kibana
Not affected
Red Hat Software Collections
rh-nodejs10-nodejs
Not affected
Red Hat Software Collections
rh-nodejs4-nodejs
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Application Runtimes Node.js 10 | rhoar-nodejs-1:10.9.0-1.el7 | Fixed | RHSA-2018:2553 |
| Red Hat OpenShift Application Runtimes Node.js 8 | rhoar-nodejs-1:8.11.4-2.el7 | Fixed | RHSA-2018:2552 |
| Red Hat OpenShift Container Platform 3.11 | jenkins-2-plugins-0:3.11.1539805268-1.el7 | Fixed | RHSA-2018:3537 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-nodejs6-nodejs-0:6.11.3-6.el6 | Fixed | RHSA-2018:2944 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-nodejs6-nodejs-0:6.11.3-6.el6 | Fixed | RHSA-2018:2944 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs6-nodejs-0:6.11.3-7.el7 | Fixed | RHSA-2018:2944 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs8-nodejs-0:8.11.4-1.el7 | Fixed | RHSA-2018:2949 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | rh-nodejs6-nodejs-0:6.11.3-7.el7 | Fixed | RHSA-2018:2944 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | rh-nodejs6-nodejs-0:6.11.3-7.el7 | Fixed | RHSA-2018:2944 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | rh-nodejs8-nodejs-0:8.11.4-1.el7 | Fixed | RHSA-2018:2949 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-nodejs6-nodejs-0:6.11.3-7.el7 | Fixed | RHSA-2018:2944 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-nodejs8-nodejs-0:8.11.4-1.el7 | Fixed | RHSA-2018:2949 |
| Red Hat Enterprise Linux 8 | nodejs:10/nodejs | Not affected | n/a |
| Red Hat Mobile Application Platform 4 | nodejs | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.10 | logging-auth-proxy | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.10 | logging-kibana | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | logging-auth-proxy | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | logging-kibana | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.2 | logging-auth-proxy | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.2 | logging-kibana | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.3 | logging-auth-proxy | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.3 | logging-kibana | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.4 | logging-auth-proxy | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.4 | logging-kibana | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.5 | logging-auth-proxy | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.5 | logging-kibana | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.6 | logging-auth-proxy | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.6 | logging-kibana | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.7 | logging-auth-proxy | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.7 | logging-kibana | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.9 | logging-auth-proxy | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.9 | logging-kibana | Not affected | n/a |
| Red Hat OpenShift Enterprise 3.0 | logging-auth-proxy | Not affected | n/a |
| Red Hat OpenShift Enterprise 3.0 | logging-kibana | Not affected | n/a |
| Red Hat OpenShift Enterprise 3.1 | logging-auth-proxy | Not affected | n/a |
| Red Hat OpenShift Enterprise 3.1 | logging-kibana | Not affected | n/a |
| Red Hat Software Collections | rh-nodejs10-nodejs | Not affected | n/a |
| Red Hat Software Collections | rh-nodejs4-nodejs | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Openshift Container Platform 3.x versions are potentially vulnerable via the jenkins-slave-nodejs and jenkins-agent-nodejs containers. However a build would have to occur with a malicious jenkins pipeline, or nodejs source code supplied by an attacker, reducing the impact of this flaw to moderate. Both container images used nodejs delivered from Red Hat Software Collections.
Red Hat mitigation
On Openshift Container Platform 3.x you can override the container image used on the Jenkins Slave by specifying the JENKINS_SLAVE_IMAGE environment variable in your jenkins deployment configuration. Ref: https://github.com/openshift/jenkins/blob/8e1ab16fb5f44d6570018c5dfa3407692fdba6e5/2/contrib/jenkins/kube-slave-common.sh#L27-L33
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (17 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 8.03% (0.08028) | 94.61th | v5 (v2026.06.15) |
| Jun 15, 2026 | 8.03% (0.08028) | 94.02th | v5 (v2026.06.15) |
| Feb 11, 2026 | 0.80% (0.00797) | 73.57th | v4 (v2025.03.14) |
| Jul 20, 2024 | 1.64% (0.01643) | 87.72th | v3 (v2023.03.01) |
| Mar 31, 2024 | 1.64% (0.01643) | 87.30th | v3 (v2023.03.01) |
| Feb 12, 2024 | 1.75% (0.01752) | 87.53th | v3 (v2023.03.01) |
| Jan 12, 2024 | 2.05% (0.02054) | 87.81th | v3 (v2023.03.01) |
| Aug 15, 2023 | 2.93% (0.02930) | 89.52th | v3 (v2023.03.01) |
| Mar 7, 2023 | 3.57% (0.03569) | 90.17th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.18% (0.01183) | 61.76th | v2 (v2022.01.01) |
| Oct 19, 2022 | 1.18% (0.01183) | 60.79th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.18% (0.01183) | 58.77th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.18% (0.01183) | 35.15th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.86% (0.01865) | 48.06th | v1 |
| Jan 6, 2022 | 1.86% (0.01865) | 47.54th | v1 |
| Sep 1, 2021 | 1.86% (0.01865) | 76.13th | v1 |
| Apr 14, 2021 | 1.86% (0.01865) | 0.00th | v1 |
References (12)
- http://www.securityfocus.com/bid/105127 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:2552 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2553 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2944 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2949 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3537 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-12115 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1620219 Issue Tracking
- https://nodejs.org/en/blog/vulnerability/august-2018-security-releases/ x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-12115
- https://security.gentoo.org/glsa/202003-48 vendor-advisoryx_refsource_GENTOO
- https://www.cve.org/CVERecord?id=CVE-2018-12115
Change history (0)
No recorded changes yet.