Wind River Support Network

HomeDefectsLIN1019-10960
Fixed

LIN1019-10960 : Security Advisory - nodejs - CVE-2024-22017

Created: Feb 18, 2024    Updated: Feb 22, 2024
Resolved Date: Feb 19, 2024
Found In Version: 10.19.45.1
Severity: Standard
Applicable for: Wind River Linux LTS 19
Component/s: Userspace

Description

nodejs: setuid() does not drop all privileges due to io_uring

https://github.com/nodejs/node/releases

CREATE(Triage):(User=admin) CVE-2024-22017 (https://nvd.nist.gov/vuln/detail/CVE-2024-22017)
Live chat
Online