CVE-2023-1255

Buffer Over-read
Affects
Node.js
in
Node.js
No items found.
Versions
>=17.0.0 <=17.9.1 >=18.0.0 <18.16.1 >=19.0.0 <=19.9.0 >=20.0.0 <20.3.1

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Node.js is a JavaScript runtime built on Chrome's V8 JavaScript engine. It uses an event-driven, non-blocking I/O model and is widely used for web applications and server-side development. Node.js compiles its own copy of OpenSSL from deps/openssl in the Node.js source tree, and the built-in crypto module, including crypto.createDecipheriv(), uses that bundled copy, with its hand-optimized assembly code, for symmetric ciphers. Node.js publishes official 64-bit ARM builds, and Node.js 17.x was the first release line to bundle OpenSSL 3.0.

A vulnerability (CVE-2023-1255) has been identified in the OpenSSL 3.0 library bundled with Node.js. On 64-bit ARM, OpenSSL's assembly implementation of AES-XTS decryption reads past the end of the ciphertext buffer when the ciphertext length is 4 mod 5 in 16-byte blocks, for example 144 or 1024 bytes. If the memory right after the buffer is not mapped, the read crashes the process, causing a denial of service.

This flaw maps to CWE-126 (Buffer Over-read), a form of CWE-125 (Out-of-bounds Read), where software reads beyond the end of the buffer it is working on. In OpenSSL, the 64-bit ARM AES-XTS decryption routine processes the ciphertext in groups of five blocks, and for lengths that leave four blocks over it loaded one block too far. The extra bytes are not used in the output, so the over-read is harmless unless it touches unmapped memory.

AES-XTS is a cipher mode designed for disk and storage encryption and is rarely used for network data. An attacker would need an application that decrypts AES-XTS data on 64-bit ARM and would need to control both the ciphertext's size and where its buffer sits in memory, which OpenSSL considers fairly unlikely. In Node.js, the cipher is reachable through crypto.createDecipheriv() with aes-128-xts or aes-256-xts. This issue affects the Node.js 17.x, 18.x, 19.x and 20.x release lines up to the versions listed above.

Details

Module Info

  • Product: Node.js
  • Affected packages: node (bundles OpenSSL 3.0 under deps/openssl)
  • Affected versions: >=17.0.0 <=17.9.1 >=18.0.0 <18.16.1 >=19.0.0 <=19.9.0 >=20.0.0 <20.3.1
  • GitHub repository: https://github.com/nodejs/node
  • Published packages: https://nodejs.org/en/download
  • Package manager: Not applicable; Node.js is distributed as runtime builds from nodejs.org rather than as a published npm package
  • Fixed in: Node.js 18.16.1 and 20.3.1 (June 20, 2023), security releases that upgraded the bundled OpenSSL to 3.0.9; this CVE is also listed in the Node.js NES v16.20.3 release notes (16.x line, shipped July 30, 2024). Node.js 17.x and 19.x never received a fix

Vulnerability Info

This Medium-severity vulnerability is found in OpenSSL 3.0.0 through 3.0.8 (and 3.1.0), the versions bundled by Node.js 17.x through 20.x before the releases listed above. NVD assigns a CVSS v3.1 score of 5.9; OpenSSL rates the issue Low under its own severity policy, including in its FIPS provider.

XTS encrypts storage in fixed-size 16-byte blocks, and OpenSSL's 64-bit ARM implementation in aesv8-armx.pl speeds up decryption by handling five blocks per loop iteration before dealing with any blocks left over. In the vulnerable versions, the code path for exactly four leftover blocks loaded input from one block beyond the ciphertext. The fix stops that extra load so decryption reads only the ciphertext it was given. See the OpenSSL 3.0 fix commit for the exact change.

The over-read does not change the decrypted output and is not known to disclose data. Its only known impact is a crash when the bytes after the buffer fall on an unmapped page, which an attacker can only arrange with control over both the buffer's length and its placement.

Note: OpenSSL 1.1.1 and 1.0.2 are not affected, so Node.js release lines that bundle them, including 16.x and earlier, are not exposed by this issue. Node.js on x86-64 and other non-ARM64 platforms, and applications that do not use AES-XTS, are not exposed either.

Mitigation

Users of the affected components should apply one of the following mitigations:

  • Upgrade to a currently supported Node.js LTS release (22.x or 24.x), both of which bundle OpenSSL 3.5, which includes this fix.
  • Migrate affected applications away from the End-of-Life Node.js release lines.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support, through Node.js NES.

Credits

  • Anton Romanov from Amazon (reporter)
  • Nevine Ebeid from Amazon (remediation developer)
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
Medium
ID
CVE-2023-1255
PROJECT Affected
Node.js
Versions Affected
>=17.0.0 <=17.9.1 >=18.0.0 <18.16.1 >=19.0.0 <=19.9.0 >=20.0.0 <20.3.1
NES Versions Affected
Published date
October 8, 2026
≈ Fix date
July 30, 2024
Category
Buffer Over-read
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Node.js
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.