Back

MEDIUM

vm2 before 3.12.2 Memory Disclosure via zlib Buffer Pool

Published Sep 27, 2026

Description

vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and buffer.byteLength === length) to Buffers returned from host builtin modules. When an application explicitly exposes Node's zlib module through NodeVM's builtin allowlist (require: { builtin: ['zlib'] }), zlib.deflateSync can return a Buffer backed by Node's shared small-buffer pool whose .buffer is the entire pool. Untrusted guest code can construct a full-width view of that ArrayBuffer (Buffer.from(result.buffer, 0, result.buffer.byteLength)) to read and modify bytes belonging to unrelated host buffers, disclosing and corrupting host-realm memory across the sandbox boundary.

Affected products

Remediation

Red Hat statement

This vulnerability is rated as an Important severity because untrusted guest code can break sandbox isolation, allowing the disclosure and modification of host memory space. Exploitation requires an explicit, non-default configuration where the application grants the guest environment access to Node's builtin zlib compression module. Red Hat products shipping this library do not expose the vulnerable feature in their active execution paths, which prevents exposure under default configurations.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 27, 2026
Updated Oct 1, 2026
Reserved Sep 26, 2026
CISA Vulnrichment
Updated Oct 1, 2026
NVD
Status Deferred
Modified Sep 27, 2026
Red Hat
Severity Important
Public date Sep 27, 2026