CVE-2021-4160
Patch Available.
This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.
Overview
Node.js is a JavaScript runtime built on Chrome's V8 JavaScript engine. It uses an event-driven, non-blocking I/O model and is widely used for web applications and server-side development. Node.js does not rely on a system cryptography library by default: it compiles its own copy of OpenSSL from deps/openssl in the Node.js source tree, and the built-in crypto and tls modules sit on top of that bundled copy. A flaw in the bundled OpenSSL therefore reaches Node.js directly.
A vulnerability (CVE-2021-4160) has been identified in the OpenSSL library bundled with Node.js. OpenSSL's MIPS32 and MIPS64 assembly code for big-number squaring contains a carry propagation bug, so BN_mod_exp and the arithmetic built on it can return incorrect results. Many elliptic-curve algorithms are affected, including some of the TLS 1.3 default curves.
Incorrect results in the arithmetic underneath RSA, DSA, Diffie-Hellman and elliptic-curve cryptography are a cryptographic weakness: the algorithms are sound, but the implementation does not compute them correctly. When a private-key operation produces wrong output, the faulty results can, under the right conditions, leak information about the key.
The OpenSSL project considers practical attacks unlikely. Attacks against RSA and DSA are believed to be very difficult; attacks against DH are considered only just feasible, because most of the work to deduce key information can be done offline, but they need significant resources and a server that reuses its DH private key across many clients, which OpenSSL has not allowed since CVE-2016-0701. The issue only affects Node.js running on MIPS. Official nodejs.org binaries are not built for MIPS, so exposure is limited to Node.js compiled from source for a MIPS target, which the bundled OpenSSL build configuration supports through its linux64-mips64 assembly target. This issue affects the Node.js 10.x (from 10.16.0, the first release to bundle OpenSSL 1.1.1), 11.x (from 11.9.0), 12.x, 13.x, 14.x, 15.x, 16.x and 17.x release lines up to the versions listed above.
Details
Module Info
- Product: Node.js
- Affected packages: node (bundles OpenSSL under deps/openssl)
- Affected versions: >=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <12.22.8 >=13.0.0 <=13.14.0 >=14.0.0 <14.19.0 >=15.0.0 <=15.14.0 >=16.0.0 <16.14.0 >=17.0.0 <17.3.0
- GitHub repository: https://github.com/nodejs/node
- Published packages: https://nodejs.org/en/download
- Package manager: Not applicable; Node.js is distributed as runtime builds from nodejs.org rather than as a published npm package
- Fixed in: Node.js 12.22.8 (December 16, 2021), 17.3.0 (December 17, 2021), 14.19.0 (February 1, 2022) and 16.14.0 (February 8, 2022), which upgraded the bundled OpenSSL to 1.1.1m or 3.0.1 while those lines were still supported; Node.js NES v16.20.3 (16.x line, shipped July 30, 2024), a later post-EOL cumulative build carrying the same fix. Node.js 10.x, 11.x, 13.x and 15.x reached End-of-Life before the fix and never received it
Vulnerability Info
This Medium-severity vulnerability is found in the OpenSSL library that Node.js bundles and statically links at deps/openssl, in Node.js releases whose bundled OpenSSL is 1.1.1 through 1.1.1l or 3.0.0, when built for MIPS. NVD assigns a CVSS v3.1 score of 5.9; OpenSSL rates the issue Moderate under its own severity policy.
Modular exponentiation (BN_mod_exp) and the elliptic-curve arithmetic that share its primitives depend on a squaring routine that must carry every overflow bit into the next word. On MIPS32 and MIPS64, OpenSSL replaces the generic C routine with hand-written assembly, and that assembly dropped a carry in some cases, producing a wrong result rather than an error. See the OpenSSL 1.1.1 fix commit for the exact change.
An attacker would need to observe many private-key operations that hit the faulty path, typically by connecting repeatedly to a TLS server that reuses the same Diffie-Hellman private key, and then do substantial offline computation to recover information about that key. OpenSSL did not analyze the impact in detail because these prerequisites are considered unlikely.
Note: Only MIPS builds are affected. Node.js on x64, arm64, armv7, ppc64le, s390x, Windows or macOS is not exposed by this issue, whatever its version.
Mitigation
The Node.js 10.x, 11.x, 12.x, 13.x, 14.x, 15.x, 16.x and 17.x release lines are all past their support window and will not receive further upstream updates.
Users of the affected components should apply one of the following mitigations:
- Upgrade to a currently supported Node.js LTS release (22.x or 24.x), both of which bundle OpenSSL 3.5, long past the fix.
- Migrate affected applications away from the End-of-Life Node.js release lines.
- Leverage a commercial support partner like HeroDevs for post-EOL security support, through Node.js NES.
Credits
- Bernd Edlinger (finder and remediation developer)