libuv: buffer overflow in realpath
Published Sep 18, 2020
7.8
HIGHCVSS 3.1
EPSS 0.71%
Description
The implementation of realpath in libuv < 10.22.1, < 12.18.4, and < 14.9.0 used within Node.js incorrectly determined the buffer size which can result in a buffer overflow if the resolved path is longer than 256 bytes.
Affected products
-
Affected
- ≥ 10.0, < 10.22.1
- ≥ 11.0, < 11.*
- ≥ 12.0, < 12.18.4
- ≥ 13.0, < 13.*
- ≥ 14.0, < 14.9.0
- ≥ 4.0, < 4.*
- ≥ 5.0, < 5.*
- ≥ 6.0, < 6.*
- ≥ 7.0, < 7.*
- ≥ 8.0, < 8.*
- ≥ 9.0, < 9.*
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
No data.
Red Hat Enterprise Linux 8
nodejs:10-8030020210118191659.229f0a1c
Fixed · RHSA-2021:0548
Red Hat Enterprise Linux 8
nodejs:12-8020020201007080935.4cda2c84
Fixed · RHSA-2020:4272
Red Hat Enterprise Linux 8.1 Extended Update Support
nodejs:12-8010020201006223055.c27ad7f8
Fixed · RHSA-2020:4903
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs10-nodejs-0:10.23.1-2.el7
Fixed · RHSA-2021:0521
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs12-nodejs-0:12.18.4-3.el7
Fixed · RHSA-2020:5086
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs10-nodejs-0:10.23.1-2.el7
Fixed · RHSA-2021:0521
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs12-nodejs-0:12.18.4-3.el7
Fixed · RHSA-2020:5086
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs10-nodejs-0:10.23.1-2.el7
Fixed · RHSA-2021:0521
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs12-nodejs-0:12.18.4-3.el7
Fixed · RHSA-2020:5086
Red Hat Enterprise Linux 8
libuv
Not affected
Red Hat Enterprise Linux 8
nodejs:14/nodejs
Not affected
Red Hat OpenStack Platform 13 (Queens) Operational Tools
libuv
Not affected
Red Hat Quay 3
quay
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | nodejs:10-8030020210118191659.229f0a1c | Fixed | RHSA-2021:0548 |
| Red Hat Enterprise Linux 8 | nodejs:12-8020020201007080935.4cda2c84 | Fixed | RHSA-2020:4272 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | nodejs:12-8010020201006223055.c27ad7f8 | Fixed | RHSA-2020:4903 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs10-nodejs-0:10.23.1-2.el7 | Fixed | RHSA-2021:0521 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs12-nodejs-0:12.18.4-3.el7 | Fixed | RHSA-2020:5086 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs10-nodejs-0:10.23.1-2.el7 | Fixed | RHSA-2021:0521 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs12-nodejs-0:12.18.4-3.el7 | Fixed | RHSA-2020:5086 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs10-nodejs-0:10.23.1-2.el7 | Fixed | RHSA-2021:0521 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs12-nodejs-0:12.18.4-3.el7 | Fixed | RHSA-2020:5086 |
| Red Hat Enterprise Linux 8 | libuv | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nodejs:14/nodejs | Not affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) Operational Tools | libuv | Not affected | n/a |
| Red Hat Quay 3 | quay | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
As shipped in Red Hat Software Collections (nodejs-10 & nodejs-12) as well as Red Hat Enterprise Linux 8 (nodejs-10 and nodejs-12), no incorrect use of the `UV__PATH_MAX` macro were found. Although the releases of libuv contained in these versions of nodejs are considered "Affected", it is considered not feasible to trigger the flaw. NodeJS is included in Red Hat Quay as a dependency of Yarn which is only used while building Red Hat Quay, and not during runtime. Red Hat Enterprise Linux 8 ships libuv-1.23.1, which is not vulnerable to this flaw.
References (13)
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00011.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00023.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-8252 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1879315 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29122 Advisory
- https://hackerone.com/reports/965914 x_refsource_MISCPermissions RequiredThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4OOYAMJVLLCLXDTHW3V5UXNULZBBK4O6/ vendor-advisoryx_refsource_FEDORA
- https://nodejs.org/en/blog/vulnerability/september-2020-security-releases/ x_refsource_MISCVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-8252
- https://security.gentoo.org/glsa/202009-15 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20201009-0004/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4548-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-8252
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data