CVE-2021-22883
Description
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.
CWE
- CWE-400 — Denial of Service (CWE-400)
Affected
- NodeJS / Node — v=4.0 <4.* [affected]; v=5.0 <5.* [affected]; v=6.0 <6.* [affected]; v=7.0 <7.* [affected]; v=8.0 <8.* [affected]; v=9.0 <9.* [affected]; v=10.0 <10.24.0 [affected]; v=11.0 <11.* [affected]; v=12.0 <12.21.0 [affected]; v=13.0 <13.* [affected]; v=14.0 <14.16.0 [affected]; v=15.0 <15.10.0 [affected]
CVSS
- (none)
References
- https://nodejs.org/en/blog/vulnerability/february-2021-security-releases/ x_refsource_MISC
- https://hackerone.com/reports/1043360 x_refsource_MISC
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4FRS5ZVK4ZQ7XIJQNGIKUXG2DJFHLO7/ vendor-advisory, x_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F45Y7TXSU33MTKB6AGL2Q5V5ZOCNPKOG/ vendor-advisory, x_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HSYFUGKFUSZ27M5TEZ3FKILWTWFJTFAZ/ vendor-advisory, x_refsource_FEDORA
- https://www.oracle.com/security-alerts/cpuApr2021.html x_refsource_MISC
- https://security.netapp.com/advisory/ntap-20210416-0001/ x_refsource_CONFIRM
- https://www.oracle.com//security-alerts/cpujul2021.html x_refsource_MISC
- https://www.oracle.com/security-alerts/cpuoct2021.html x_refsource_MISC
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf x_refsource_CONFIRM
Source
cvelistV5-main/cves/2021/22xxx/CVE-2021-22883.json