CVE-2023-6129

Denial of Service
Affects
Node.js
in
Node.js
No items found.
Versions
>=17.0.0 <=17.9.1 >=18.0.0 <18.19.1 >=19.0.0 <=19.9.0 >=20.0.0 <20.11.1 >=21.0.0 <21.6.2

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Node.js is a JavaScript runtime built on Chrome's V8 JavaScript engine. It uses an event-driven, non-blocking I/O model and is widely used for web applications and server-side development. Node.js compiles its own copy of OpenSSL from deps/openssl in the Node.js source tree, including OpenSSL's hand-written assembly for each CPU, and the built-in crypto, tls and https modules run on that bundled copy. Node.js publishes official builds for 64-bit little-endian PowerPC (linux-ppc64le), and Node.js 17.x was the first release line to bundle OpenSSL 3.0.

A vulnerability (CVE-2023-6129) has been identified in the OpenSSL 3.0 library bundled with Node.js. On PowerPC processors that support the PowerISA 2.07 vector instructions, OpenSSL's POLY1305 MAC implementation restores saved vector registers in a different order than it saved them, so some registers hold the wrong values when control returns to the caller. The resulting corruption of the application's internal state most likely leads to incorrect results or a crash, causing a denial of service, but in the worst case could give an attacker control of the process.

This flaw maps to CWE-440 (Expected Behavior Violation), where a function does not keep a promise its callers rely on; NVD also lists CWE-787 (Out-of-bounds Write). On PowerPC, a function that uses certain vector registers must hand them back unchanged, and compiled code around it relies on that. OpenSSL's POLY1305 assembly saved those registers in one order and restored them in another, silently changing values that the calling code expected to be preserved.

POLY1305 is most often used as part of the ChaCha20-Poly1305 cipher in TLS 1.2 and 1.3. If a TLS server allows that cipher, a client can choose it, so a Node.js TLS or HTTPS server running on an affected PowerPC system can be pushed onto the vulnerable code by a malicious client; Node.js's default TLS settings include ChaCha20-Poly1305. Applications can also reach it directly through crypto.createCipheriv() with chacha20-poly1305. OpenSSL knew of no concrete application that was affected. This issue affects the Node.js 17.x through 21.x release lines up to the versions listed above.

Details

Module Info

  • Product: Node.js
  • Affected packages: node (bundles OpenSSL 3.0 under deps/openssl)
  • Affected versions: >=17.0.0 <=17.9.1 >=18.0.0 <18.19.1 >=19.0.0 <=19.9.0 >=20.0.0 <20.11.1 >=21.0.0 <21.6.2
  • GitHub repository: https://github.com/nodejs/node
  • Published packages: https://nodejs.org/en/download
  • Package manager: Not applicable; Node.js is distributed as runtime builds from nodejs.org rather than as a published npm package
  • Fixed in: Node.js 18.19.1, 20.11.1 and 21.6.2 (all February 14, 2024), security releases that upgraded the bundled OpenSSL to 3.0.13; this CVE is also listed in the Node.js NES v16.20.3 release notes (16.x line, shipped July 30, 2024). Node.js 17.x and 19.x never received a fix

Vulnerability Info

This Medium-severity vulnerability is found in OpenSSL 3.0.0 through 3.0.12 (and 3.1.0 through 3.1.4 and 3.2.0), the versions bundled by Node.js 17.x through 21.x before the releases listed above. NVD assigns a CVSS v3.1 score of 6.5; OpenSSL rates the issue Low under its own severity policy.

Under the PowerPC calling convention, vector registers v20 to v31 are non-volatile: any function that uses them must save their contents on entry and put them back before returning. OpenSSL's poly1305-ppc.pl assembly, used on POWER8 and newer processors, did save and restore them, but the restore sequence did not mirror the save sequence, so values ended up in the wrong registers. The fix restores the registers in the same order they were saved. See the OpenSSL 3.0 fix commit for the exact change.

What happens next depends on how the calling code uses those registers. If it does not keep anything in them across the call, nothing happens. If it does, calculations can silently go wrong or the process can crash. OpenSSL notes that unless the compiler keeps pointers in these vector registers, takeover of the process is unlikely; NVD rates the attack complexity as high for the same reason.

Note: Only PowerPC builds running on processors with PowerISA 2.07 vector support are affected. Node.js on x86-64, ARM and other platforms is not exposed by this issue, and OpenSSL 1.1.1 and 1.0.2 are not affected, so Node.js 16.x and earlier are not exposed either.

Mitigation

Users of the affected components should apply one of the following mitigations:

  • Upgrade to a currently supported Node.js LTS release (22.x or 24.x), both of which bundle OpenSSL 3.5, which includes this fix.
  • Where an upgrade is not yet possible on PowerPC, remove ChaCha20-Poly1305 from the TLS cipher list (the ciphers and, for TLS 1.3, ciphersuites options) and avoid it in crypto.createCipheriv().
  • Leverage a commercial support partner like HeroDevs for post-EOL security support, through Node.js NES.

Credits

  • Sverker Eriksson from Ericsson (finder)
  • Rohan McLure from IBM (remediation developer)
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
Medium
ID
CVE-2023-6129
PROJECT Affected
Node.js
Versions Affected
>=17.0.0 <=17.9.1 >=18.0.0 <18.19.1 >=19.0.0 <=19.9.0 >=20.0.0 <20.11.1 >=21.0.0 <21.6.2
NES Versions Affected
Published date
October 8, 2026
≈ Fix date
July 30, 2024
Category
Denial of Service
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Node.js
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.