CVE-2023-0215

Use After Free
Affects
Node.js
in
Node.js
No items found.
Versions
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <16.19.1 >=17.0.0 <=17.9.1 >=18.0.0 <18.14.1 >=19.0.0 <19.6.1

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Node.js is a JavaScript runtime built on Chrome's V8 JavaScript engine. It uses an event-driven, non-blocking I/O model and is widely used for web applications and server-side development. Node.js compiles its own copy of OpenSSL from deps/openssl in the Node.js source tree and statically links it into the runtime, so a flaw in the bundled OpenSSL is present in every Node.js binary built from that tree.

A vulnerability (CVE-2023-0215) has been identified in the OpenSSL library bundled with Node.js. OpenSSL's BIO_new_NDEF() helper, used to stream ASN.1 data for S/MIME, CMS and PKCS#7 output, can fail, for example when a CMS recipient's public key is invalid, and free the filter it created while leaving the caller's BIO still pointing at it. When the caller then removes that filter from the chain, OpenSSL uses freed memory, which will most likely crash the process.

This flaw maps to CWE-416 (Use After Free), where software keeps using memory after it has been released. In OpenSSL, the failure path of BIO_new_NDEF() freed the new filter BIO but did not undo the BIO chain it had started to build, so a stale pointer to the freed filter stayed in the caller's BIO. OpenSSL's own S/MIME and PEM streaming code follows a failed call with BIO_pop(), which dereferences that stale pointer, so an attacker who can supply the input that causes the failure, such as an invalid recipient key, can crash the process and cause a denial of service.

The flaw is reachable through OpenSSL's streaming output functions: PEM_write_bio_ASN1_stream(), PEM_write_bio_CMS_stream(), PEM_write_bio_PKCS7_stream(), SMIME_write_ASN1(), SMIME_write_CMS() and SMIME_write_PKCS7(), along with i2d_ASN1_bio_stream(), BIO_new_CMS(), BIO_new_PKCS7(), i2d_CMS_bio_stream() and i2d_PKCS7_bio_stream(). The openssl cms and smime command-line tools are affected too. Node.js's built-in modules do not call these functions, so exposure in a Node.js deployment depends on native addons or embedders that use them through the bundled OpenSSL. This issue affects every Node.js release line from 4.x through 19.x whose bundled OpenSSL is 1.0.2, 1.1.1 or 3.0, up to the versions listed above.

Details

Module Info

  • Product: Node.js
  • Affected packages: node (bundles OpenSSL under deps/openssl)
  • Affected versions: >=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <16.19.1 >=17.0.0 <=17.9.1 >=18.0.0 <18.14.1 >=19.0.0 <19.6.1
  • GitHub repository: https://github.com/nodejs/node
  • Published packages: https://nodejs.org/en/download
  • Package manager: Not applicable; Node.js is distributed as runtime builds from nodejs.org rather than as a published npm package
  • Fixed in: Node.js 14.21.3, 16.19.1, 18.14.1 and 19.6.1 (all February 16, 2023), security releases that upgraded the bundled OpenSSL to 1.1.1t or 3.0.8; Node.js NES v16.20.3 (16.x line, shipped July 30, 2024), a later cumulative build carrying the same fix. The other release lines listed above never received an updated OpenSSL

Vulnerability Info

This High-severity vulnerability is found in the OpenSSL library that Node.js bundles and statically links at deps/openssl, in Node.js releases whose bundled OpenSSL predates 1.1.1t, 3.0.8 or 1.0.2zg. NVD assigns a CVSS v3.1 score of 7.5; OpenSSL rates the issue Moderate under its own severity policy.

BIO_new_NDEF() takes a BIO from the caller, places a new ASN.1 filter BIO in front of it, and returns the head of that chain. On success, the returned chain owns the caller's BIO. On failure, it is supposed to leave the caller's BIO exactly as it was. In the vulnerable versions, a failure after the filter had been linked in freed the filter but left the caller's BIO attached to it, so the BIO chain was invalid and the next operation on it touched freed memory. The fix detaches the filter from the caller's BIO with BIO_pop() before freeing it on any failure, so the caller gets its BIO back unchanged, and it now also checks the setup steps that previously ignored errors. See the OpenSSL 1.1.1 fix commit and the OpenSSL 3.0 fix commit for the exact changes.

Exploitation requires an application that produces streamed S/MIME, CMS or PKCS#7 output with the affected functions and lets an attacker influence the input that makes BIO_new_NDEF() fail, such as a recipient certificate with an invalid public key. The expected result is a crash, and so a denial of service, of that process.

Note: Node.js applications that rely only on the built-in crypto, tls and https modules do not call the affected streaming functions and are not exposed by this issue.

Mitigation

Users of the affected components should apply one of the following mitigations:

  • Upgrade to a currently supported Node.js LTS release (22.x or 24.x), both of which bundle OpenSSL 3.5, which includes this fix.
  • Migrate affected applications away from the End-of-Life Node.js release lines.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support, through Node.js NES.

Credits

  • Octavio Galland from the Max Planck Institute for Security and Privacy (reporter)
  • Marcel Böhme from the Max Planck Institute for Security and Privacy (reporter)
  • Viktor Dukhovni (remediation developer)
  • Matt Caswell from the OpenSSL project (remediation developer)
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
High
ID
CVE-2023-0215
PROJECT Affected
Node.js
Versions Affected
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <16.19.1 >=17.0.0 <=17.9.1 >=18.0.0 <18.14.1 >=19.0.0 <19.6.1
NES Versions Affected
Published date
October 8, 2026
≈ Fix date
July 30, 2024
Category
Use After Free
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Node.js
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.