CVE-2025-47153
published 2025-05-01CVE-2025-47153: Certain build processes for libuv and Node.js for 32-bit systems, such as for the nodejs binary package through nodejs_20.19.0+dfsg-2_i386.deb for Debian…
PriorityP334medium6.5CVSS 3.1
AVNACHPRNUINSCCLILAL
EPSS
0.36%
28.3th percentile
Certain build processes for libuv and Node.js for 32-bit systems, such as for the nodejs binary package through nodejs_20.19.0+dfsg-2_i386.deb for Debian GNU/Linux, have an inconsistent off_t size (e.g., building on i386 Debian always uses _FILE_OFFSET_BITS=64 for the libuv dynamic library, but uses the _FILE_OFFSET_BITS global system default of 32 for nodejs), leading to out-of-bounds access. NOTE: this is not a problem in the Node.js software itself. In particular, the Node.js website's download page does not offer prebuilt Node.js for Linux on i386.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nodejs | < nodejs 18.20.4+dfsg-1~deb12u1 (bookworm) | nodejs 18.20.4+dfsg-1~deb12u1 (bookworm) |
| debian | trixie | nodejs_0.10.0~dfsg1-1_i386.deb – nodejs_20.19.0+dfsg-2_i386.deb | — |
| nodejs | nodejs | >= 0 < 12.22.12~dfsg-1~deb11u7 | 12.22.12~dfsg-1~deb11u7 |
| nodejs | nodejs | >= 0 < 18.20.4+dfsg-1~deb12u1 | 18.20.4+dfsg-1~deb12u1 |
| nodejs | nodejs | >= 0 < 20.19.0+dfsg1-1 | 20.19.0+dfsg1-1 |
| nodejs | nodejs | >= 0 < 20.19.0+dfsg1-1 | 20.19.0+dfsg1-1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
nodejs: libuv: Out-of-Bounds Access Due to Inconsistent off_t Size in libuv and Node.js Build on i386
vendor_redhat·2025-05-01·CVSS 6.5
CVE-2025-47153 [MEDIUM] CWE-1102 nodejs: libuv: Out-of-Bounds Access Due to Inconsistent off_t Size in libuv and Node.js Build on i386
nodejs: libuv: Out-of-Bounds Access Due to Inconsistent off_t Size in libuv and Node.js Build on i386
Certain build processes for libuv and Node.js for 32-bit systems, such as for the nodejs binary package through nodejs_20.19.0+dfsg-2_i386.deb for Debian GNU/Linux, have an inconsistent off_t size (e.g., building on i386 Debian always uses _FILE_OFFSET_BITS=64 for the libuv dynamic library, but uses the _FILE_OFFSET_BITS global system default of 32 for nodejs), leading to out-of-bounds access. NOTE: this is not a problem in the Node.js software itself. In particular, the Node.js website's download page does not offer prebuilt Node.js for Linux on i386.
A flaw was found in the build process of libuv and Node.js on 32-bit systems. This vulnerability allows out-of-bounds memory access via m
Debian
CVE-2025-47153: nodejs - Certain build processes for libuv and Node.js for 32-bit systems, such as for th...
vendor_debian·2025·CVSS 6.5
CVE-2025-47153 [MEDIUM] CVE-2025-47153: nodejs - Certain build processes for libuv and Node.js for 32-bit systems, such as for th...
Certain build processes for libuv and Node.js for 32-bit systems, such as for the nodejs binary package through nodejs_20.19.0+dfsg-2_i386.deb for Debian GNU/Linux, have an inconsistent off_t size (e.g., building on i386 Debian always uses _FILE_OFFSET_BITS=64 for the libuv dynamic library, but uses the _FILE_OFFSET_BITS global system default of 32 for nodejs), leading to out-of-bounds access. NOTE: this is not a problem in the Node.js software itself. In particular, the Node.js website's download page does not offer prebuilt Node.js for Linux on i386.
Scope: local
bookworm: resolved (fixed in 18.20.4+dfsg-1~deb12u1)
bullseye: resolved (fixed in 12.22.12~dfsg-1~deb11u7)
forky: resolved (fixed in 20.19.0+dfsg1-1)
sid: resolved (fixed in 20.19.0+dfsg1-1)
trixie: resolved (fixed in 20.19.0+df
OSV
CVE-2025-47153: Certain build processes for libuv and Node
osv·2025-05-01·CVSS 6.5
CVE-2025-47153 [MEDIUM] CVE-2025-47153: Certain build processes for libuv and Node
Certain build processes for libuv and Node.js for 32-bit systems, such as for the nodejs binary package through nodejs_20.19.0+dfsg-2_i386.deb for Debian GNU/Linux, have an inconsistent off_t size (e.g., building on i386 Debian always uses _FILE_OFFSET_BITS=64 for the libuv dynamic library, but uses the _FILE_OFFSET_BITS global system default of 32 for nodejs), leading to out-of-bounds access. NOTE: this is not a problem in the Node.js software itself. In particular, the Node.js website's download page does not offer prebuilt Node.js for Linux on i386.
GHSA
GHSA-5pxx-cc47-2282: Certain build processes for libuv and Node
ghsa_unreviewed·2025-05-01
CVE-2025-47153 [MEDIUM] CWE-1102 GHSA-5pxx-cc47-2282: Certain build processes for libuv and Node
Certain build processes for libuv and Node.js for 32-bit systems, such as for the nodejs binary package through nodejs_20.19.0+dfsg-1_i386.deb for Debian GNU/Linux, have an inconsistent off_t size (e.g., building on i386 Debian always uses _FILE_OFFSET_BITS=64 for the libuv dynamic library, but uses the _FILE_OFFSET_BITS global system default of 32 for nodejs), leading to out-of-bounds access. NOTE: this is not a problem in the Node.js software itself. In particular, the Node.js website's download page does not offer prebuilt Node.js for Linux on i386.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1076350https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=922075https://bugzilla.redhat.com/show_bug.cgi?id=892601https://github.com/nodejs/node-v0.x-archive/issues/4549http://www.openwall.com/lists/oss-security/2025/05/02/2https://lists.debian.org/debian-lts-announce/2025/05/msg00003.html
2025-05-01
Published