CVE-2023-28445: Deno improperly handles resizable ArrayBuffer
Impact
Resizable ArrayBuffers passed to asynchronous native functions that are shrunk during the asynchronous operation could result in an out-of-bound read/write.
It is unlikely that this has been exploited in the wild, as the only version affected is Deno 1.32.0.
Deno Deploy users are not affected.
Patches
The problem has been resolved by disabling resizable ArrayBuffers temporarily in Deno 1.32.1. A future version of Deno will re-enable resizable ArrayBuffers with a proper fix.
Workarounds
Upgrade to Deno 1.32.1, or run with --v8-flags=--no-harmony-rab-gsab to disable resizable ArrayBuffers.
Other sources
Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Resizable ArrayBuffers passed to asynchronous functions that are shrunk during the asynchronous operation could result in an out-of-bound read/write. It is unlikely that this has been exploited in the wild, as the only version affected is Deno 1.32.0. Deno Deploy users are not affected. The problem has been resolved by disabling resizable ArrayBuffers temporarily in Deno 1.32.1. Deno 1.32.2 will re-enable resizable ArrayBuffers with a proper fix. As a workaround, run with --v8-flags=--no-harmony-rab-gsab to disable resizable ArrayBuffers.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-28445?
CVE-2023-28445 is a vulnerability that affects Deno, a runtime for JavaScript and TypeScript.
What is the impact of CVE-2023-28445?
CVE-2023-28445 can result in an out-of-bound read/write when resizable ArrayBuffers are passed to asynchronous native functions.
Has CVE-2023-28445 been exploited in the wild?
It is unlikely that CVE-2023-28445 has been exploited in the wild.
Which versions of Deno are affected by CVE-2023-28445?
Versions 1.32.0 and below of Deno are affected by CVE-2023-28445.
How can I fix CVE-2023-28445?
To fix CVE-2023-28445, upgrade Deno to version 1.32.1 or later.