This CVE record has been withdrawn due to a duplicate entry CVE-2025-23165.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References

No reference.

History

Tue, 20 May 2025 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401
References
Metrics cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Tue, 20 May 2025 22:15:00 +0000

Type Values Removed Values Added
Description In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22. This CVE record has been withdrawn due to a duplicate entry CVE-2025-23165.
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 19 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 19 May 2025 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Mon, 19 May 2025 02:00:00 +0000

Type Values Removed Values Added
Description In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.
References
Metrics cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: REJECTED

Assigner: hackerone

Published:

Updated: 2025-05-20T21:59:31.237Z

Reserved: 2025-01-11T01:00:00.618Z

Link: CVE-2025-23122

cve-icon Vulnrichment

Updated:

cve-icon NVD

Status : Rejected

Published: 2025-05-19T02:15:17.003

Modified: 2025-05-20T22:15:18.907

Link: CVE-2025-23122

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.