CVE-2024-27983highCWE-362

CVE-2024-27983: high-severity vulnerability in NodeJS Node

Published · Updated

43Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.2epss 87%
exploitation probability
87%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
1 product (14 components)
Red Hat Enterprise Linux 8
workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Fixed
10 products (396 components)
Red Hat Enterprise Linux AppStream (v. 9) · Red Hat Enterprise Linux AppStream EUS (v.9.2) · Red Hat Enterprise Linux AppStream (v. 8) · Red Hat Enterprise Linux AppStream EUS (v.8.8) · Red Hat Enterprise Linux AppStream EUS (v.9.0) · and others 5
In short

An attacker can crash a Node.js HTTP/2 server by sending specially crafted HTTP/2 frames followed by abruptly closing the connection, leaving unprocessed data in memory that causes the server to become unavailable.

Technical detail

A race condition exists in Node.js HTTP/2 implementation where sending CONTINUATION frames and abruptly terminating the TCP connection triggers premature Http2Session destruction while headers are still being processed in nghttp2 memory, leading to denial of service without requiring authentication or special privileges.

Summary generated and translated by AI from the official description.
An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in nghttp2 memory after reset when headers with HTTP/2 CONTINUATION frame are sent to the server and then a TCP connection is abruptly closed by the client triggering the Http2Session destructor while header frames are still being processed (and stored in memory) causing a race condition.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Affected products
NodeJS · Node