CVE-2021-22940: Use After Free
A flaw was found in Node.js, where it is vulnerable to a use-after-free attack. This flaw allows an attacker to exploit memory corruption to change process behavior. The highest threat from this vulnerability is to confidentiality and integrity.
Other sources
Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.
Node.js could allow a remote attacker to bypass security restrictions, caused by an incomplete fix for CVE-2021-22930 related to a use-after-free on close http2 on stream canceling. An attacker could exploit this vulnerability to corrupt memory to change process behavior.
— IBM
Node.js was vulnerable to a use after free attack where an attacker might be able to exploit memory corruption to change process behavior. The issue is a follow on to CVE-2021-22930 as the issue was not completely resolved in the fix for CVE-2021-22930.
References: https://nodejs.org/en/blog/vulnerability/aug-2021-security-releases/
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this Node.js vulnerability?
The vulnerability ID for this Node.js vulnerability is CVE-2021-22940.
What is the severity of CVE-2021-22940?
The severity of CVE-2021-22940 is high.
How does CVE-2021-22940 impact Node.js?
CVE-2021-22940 allows a remote attacker to bypass security restrictions and corrupt memory to change process behavior in Node.js.
Which versions of Node.js are affected by CVE-2021-22940?
Versions 12.22.5, 14.17.5, and prior are affected by CVE-2021-22940.
How can I fix the CVE-2021-22940 vulnerability in Node.js?
To fix the CVE-2021-22940 vulnerability in Node.js, update to version 16.6.1, 14.17.5, or 12.22.5 or later.