GHSA-wq5f-xc86-pv6w: Use After Free
Impact
A memory-related vulnerability has been discovered and fixed in the upstream librsvg dependency. When certain runtime-specific conditions apply, this vulnerability can lead to possible remote code execution (RCE) on glibc-based Linux.
Patches
Using prebuilt binaries provided by sharp?
Most people rely on the prebuilt binaries provided by sharp.
Please upgrade sharp to the latest version, currently 0.35.5, which provides librsvg 2.63.2.
Using a globally-installed librsvg?
Please ensure you are using the latest librsvg 2.63.2.
Workarounds
Add the following to your code to prevent sharp from decoding SVG images. js sharp.block({ operation: ["VipsForeignLoadSvg"] });
To avoid RCE, ensure you are using a node executable binary compiled as a Position Independent Executable (PIE). Most Linux package managers already use this security-hardening feature however be warned that the "official" Node.js binaries do not. 1
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/sharpto a version that resolves this vulnerability.Fixed in 0.35.5 - Upgrade
Upgrade
librsvgto a version that resolves this vulnerability.Fixed in 2.63.2 - Upgrade
Upgrade
sharpto a version that resolves this vulnerability.Fixed in 0.35.5 - Configuration
Add sharp.block({ operation: ["VipsForeignLoadSvg"] }) to prevent sharp from decoding SVG images.
sharp block.operation = VipsForeignLoadSvg - Configuration
Use a node executable binary compiled as a Position Independent Executable (PIE) to reduce the risk of remote code execution.
node executable Position Independent Executable (PIE) = enabled
Event History
Frequently Asked Questions
Which deployments are most exposed to remote code execution?
The stated RCE risk applies on glibc-based Linux when the runtime-specific conditions are present. The risk is specifically associated with sharp decoding SVG images through its librsvg dependency.
What must an attacker be able to do to exploit this issue?
An attacker would need to cause sharp to decode a crafted SVG image. The advisory does not provide further prerequisites or attack paths.
Are standard sharp installations affected, and what version fixes them?
Most sharp users rely on its prebuilt binaries and should upgrade sharp to version 0.35.5, which provides librsvg 2.63.2. Installations using a globally installed librsvg should ensure that librsvg is version 2.63.2.
What can be done if upgrading cannot happen immediately?
Disable SVG decoding in sharp by adding sharp.block({ operation: ["VipsForeignLoadSvg"] }); to the application. To avoid RCE, use a Node executable compiled as a Position Independent Executable (PIE); the advisory warns that official Node.js binaries do not have this hardening.