CVE-2018-7166: High severity Nodejs Node.js vulnerability

Published Aug 12, 2018
·
Updated

In all versions of Node.js 10 prior to 10.9.0, an argument processing flaw can cause Buffer.alloc() to return uninitialized memory. This method is intended to be safe and only return initialized, or cleared, memory. The third argument specifying encoding can be passed as a number, this is misinterpreted by Buffer's internal "fill" method as the start to a fill operation. This flaw may be abused where Buffer.alloc() arguments are derived from user input to return uncleared memory blocks that may contain sensitive information.

Other sources

Node.js TSC member Сковорода Никита Андреевич (Nikita Skovoroda / @ChALkeR) discovered an argument processing flaw that causes Buffer.alloc() to return uninitialized memory. This method is intended to be safe and only return initialized, or cleared, memory. The third argument specifying encoding can be passed as a number, this is misinterpreted by Buffer's internal "fill" method as the start to a fill operation. This flaw may be abused where Buffer.alloc() arguments are derived from user input to return uncleared memory blocks that may contain sensitive information.

Impact:

All versions of Node.js 6.x (LTS "Boron") are NOT vulnerable All versions of Node.js 8.x (LTS "Carbon") are NOT vulnerable All previous versions of Node.js 10.x (Current) are vulnerable

References:

https://nodejs.org/en/blog/vulnerability/august-2018-security-releases/

Red Hat

Affected Software

2 affected componentsFixes available
redhat/nodejs<10.9.0
10.9.0
Nodejs Node.js>=10.0.0<10.9.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/nodejs to a version that resolves this vulnerability.

    Fixed in 10.9.0
  2. Upgrade

    Upgrade nodejs to a version that resolves this vulnerability.

    Fixed in 10.9.0

Event History

Aug 21, 2018
CVE Published
12:29 PM
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Aug 22, 2018
Data Sourced
via Red Hat·05:31 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2018-7166?

CVE-2018-7166 is considered a critical vulnerability due to the potential exposure of sensitive data through uninitialized memory.

2

How do I fix CVE-2018-7166?

To fix CVE-2018-7166, upgrade Node.js to version 10.9.0 or later.

3

Which versions of Node.js are affected by CVE-2018-7166?

CVE-2018-7166 affects all versions of Node.js prior to 10.9.0.

4

What vulnerability type is CVE-2018-7166?

CVE-2018-7166 is categorized as an argument processing flaw in the Node.js Buffer module.

5

Can CVE-2018-7166 lead to data exposure?

Yes, CVE-2018-7166 can lead to data exposure due to the returning of uninitialized memory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203