CVE-2022-4904

Stack-based Buffer Overflow
Affects
Node.js
in
Node.js
No items found.
Versions
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.0.0 <=10.24.1 >=11.0.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <=14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <16.20.1 >=17.0.0 <=17.9.1 >=18.0.0 <18.16.0 >=19.0.0 <19.7.0

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Node.js is a JavaScript runtime built on Chrome's V8 JavaScript engine. It uses an event-driven, non-blocking I/O model and is widely used for web applications and server-side development. For asynchronous DNS resolution, the dns module's resolver functions (dns.resolve() and the dns.Resolver class) use c-ares, a C library that Node.js bundles at deps/cares and compiles into the runtime. A flaw in the bundled c-ares therefore reaches Node.js directly.

A vulnerability (CVE-2022-4904) has been identified in the c-ares library bundled with Node.js. c-ares supports a sortlist, a resolver setting that orders the addresses returned by a lookup according to preferred networks. The code that parses a sortlist string copies each entry into a fixed-size stack buffer without checking the entry's length, so an overlong entry overflows the stack. This can crash the process and may have a limited impact on confidentiality and integrity.

This flaw maps to CWE-20 (Improper Input Validation), where software does not check that input has the properties it relies on, and its effect is a stack-based buffer overflow (CWE-121). In c-ares, config_sortlist() assumed every address or netmask in the sortlist would fit in its buffer. A sortlist entry longer than that buffer writes past it, corrupting the stack.

The parsing code runs in two places: when an application calls ares_set_sortlist() directly, and when c-ares initializes and reads a sortlist line from the system resolver configuration (/etc/resolv.conf). Node.js does not call ares_set_sortlist(), so for Node.js the path is the resolver configuration, which c-ares reads whenever Node.js creates a resolver. An attacker would need to control the contents of that configuration, which is normally set by an administrator. This issue affects every Node.js release line from 4.x through 19.x up to the versions listed above.

Details

Module Info

  • Product: Node.js
  • Affected packages: node (bundles c-ares under deps/cares)
  • Affected versions: >=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.0.0 <=10.24.1 >=11.0.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <=14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <16.20.1 >=17.0.0 <=17.9.1 >=18.0.0 <18.16.0 >=19.0.0 <19.7.0
  • GitHub repository: https://github.com/nodejs/node
  • Published packages: https://nodejs.org/en/download
  • Package manager: Not applicable; Node.js is distributed as runtime builds from nodejs.org rather than as a published npm package
  • Fixed in: Node.js 19.7.0 (February 21, 2023) and 18.16.0 (April 12, 2023), which updated the bundled c-ares to 1.19.0, and 16.20.1 (June 20, 2023), which updated it to 1.19.1; Node.js NES v14.21.4 (14.x line, shipped August 24, 2024) and v12.22.13 (12.x line, shipped November 10, 2025), neither of which received an upstream fix. The other release lines listed above never received an updated c-ares

Vulnerability Info

This Low-severity vulnerability is found in c-ares before 1.19.0, the DNS resolver library that Node.js bundles and statically links at deps/cares. NVD assigns a CVSS v3.1 score of 8.6; the c-ares project itself rates the issue Low, because the sortlist is typically provided by an administrator rather than an end user.

A sortlist entry is an IP address with an optional netmask, such as 130.155.160.0/255.255.240.0. config_sortlist() splits the string into entries and copies each address, and each netmask, into small fixed-size local buffers before parsing them. In the vulnerable versions, those copies used the length of the input text without comparing it to the size of the buffer, so any entry longer than a valid address overflowed the buffer on the stack. The fix adds a length check before each copy and rejects entries that do not fit. See the c-ares fix commit for the exact change.

Exploiting this through Node.js requires the ability to write a malicious sortlist line into the resolver configuration that Node.js reads, or a Node.js native addon or embedding application that passes untrusted text to ares_set_sortlist(). The likely result is a crash of the Node.js process the next time it initializes a DNS resolver.

Note: dns.lookup(), which Node.js uses by default for http, https and net connections, goes through the operating system's resolver rather than c-ares, so applications that never use dns.resolve*() or dns.Resolver do not run the vulnerable code.

Mitigation

Users of the affected components should apply one of the following mitigations:

  • Upgrade to a currently supported Node.js LTS release (22.x or 24.x), both of which bundle a c-ares version that includes this fix.
  • Where an upgrade is not yet possible, ensure /etc/resolv.conf is writable only by administrators and contains no sortlist entries from untrusted sources.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support, through Node.js NES.

Credits

Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
Low
ID
CVE-2022-4904
PROJECT Affected
Node.js
Versions Affected
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.0.0 <=10.24.1 >=11.0.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <=14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <16.20.1 >=17.0.0 <=17.9.1 >=18.0.0 <18.16.0 >=19.0.0 <19.7.0
NES Versions Affected
Published date
October 7, 2026
≈ Fix date
August 24, 2024
Category
Stack-based Buffer Overflow
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Node.js
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.