nodejs: setuid() does not drop all privileges due to io_uring
Published Mar 19, 2024
7.3
HIGHCVSS 3.1
EPSS 0.89%
Description
setuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid(). This allows the process to perform privileged operations despite presumably having dropped such privileges through a call to setuid(). This vulnerability affects all users using version greater or equal than Node.js 18.18.0, Node.js 20.4.0 and Node.js 21.
Affected products
-
- Version 10.0StatusaffectedConstraints<10.*
- Version 11.0StatusaffectedConstraints<11.*
- Version 12.0StatusaffectedConstraints<12.*
- Version 13.0StatusaffectedConstraints<13.*
- Version 14.0StatusaffectedConstraints<14.*
- Version 15.0StatusaffectedConstraints<15.*
- Version 16.0StatusaffectedConstraints<16.*
- Version 17.0StatusaffectedConstraints<17.*
- Version 19.0StatusaffectedConstraints<19.*
- Version 20.0StatusaffectedConstraints<20.11.1
- Version 21.0StatusaffectedConstraints<21.6.2
- Version 4.0StatusaffectedConstraints<4.*
- Version 5.0StatusaffectedConstraints<5.*
- Version 6.0StatusaffectedConstraints<6.*
- Version 7.0StatusaffectedConstraints<7.*
- Version 8.0StatusaffectedConstraints<8.*
- Version 9.0StatusaffectedConstraints<9.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Node.js | Node | unaffected |
|
No data.
-
- Version 18.0.0StatusaffectedConstraints<18.18.0
- Version 20.0.0StatusaffectedConstraints<20.4.0
- Version 21.0.0StatusaffectedConstraints<21.6.1
- Version
Red Hat Enterprise Linux 8
nodejs:20-8090020240228165436.a75119d5
Fixed · RHSA-2024:1687
Red Hat Enterprise Linux 9
nodejs:20-9030020240229115828.rhel9
Fixed · RHSA-2024:1688
Red Hat Enterprise Linux 8
nodejs:16/nodejs
Not affected
Red Hat Enterprise Linux 8
nodejs:18/nodejs
Not affected
Red Hat Enterprise Linux 9
nodejs
Not affected
Red Hat Enterprise Linux 9
nodejs:18/nodejs
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | nodejs:20-8090020240228165436.a75119d5 | Fixed | RHSA-2024:1687 |
| Red Hat Enterprise Linux 9 | nodejs:20-9030020240229115828.rhel9 | Fixed | RHSA-2024:1688 |
| Red Hat Enterprise Linux 8 | nodejs:16/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nodejs:18/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | nodejs:18/nodejs | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability affects all users in active release lines 20.x, and 21.x.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:L
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed May 7, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (15 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.89% (0.00893) | 58.03th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.89% (0.00893) | 54.59th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.64% (0.00637) | 69.68th | v4 (v2025.03.14) |
| Nov 18, 2025 | 2.05% (0.02051) | 82.44th | v4 (v2025.03.14) |
| Apr 15, 2025 | 0.40% (0.00403) | 59.68th | v4 (v2025.03.14) |
| Mar 30, 2025 | 2.05% (0.02051) | 82.27th | v4 (v2025.03.14) |
| Mar 29, 2025 | 10.41% (0.10411) | 88.61th | v4 (v2025.03.14) |
| Mar 28, 2025 | 2.05% (0.02051) | 82.28th | v4 (v2025.03.14) |
| Mar 27, 2025 | 12.50% (0.12502) | 92.94th | v4 (v2025.03.14) |
| Mar 23, 2025 | 10.41% (0.10411) | 92.07th | v4 (v2025.03.14) |
| Mar 20, 2025 | 2.05% (0.02051) | 82.36th | v4 (v2025.03.14) |
| Mar 17, 2025 | 10.41% (0.10411) | 92.65th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00045) | 17.70th | v3 (v2023.03.01) |
| Jun 11, 2024 | 0.04% (0.00045) | 15.35th | v3 (v2023.03.01) |
| Mar 19, 2024 | 0.04% (0.00043) | 7.24th | v3 (v2023.03.01) |
References (7)
- http://www.openwall.com/lists/oss-security/2024/03/11/1
- https://access.redhat.com/security/cve/CVE-2024-22017 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2265727 Issue Tracking
- https://hackerone.com/reports/2170226
- https://nvd.nist.gov/vuln/detail/CVE-2024-22017
- https://security.netapp.com/advisory/ntap-20240517-0007/
- https://www.cve.org/CVERecord?id=CVE-2024-22017
Change history (0)
No recorded changes yet.