{"id":"MGASA-2021-0360","summary":"Updated libuv packages fix security vulnerability","details":"Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds\nread when uv__idna_toascii() is used to convert strings to ASCII. The pointer\np is read and increased without checking whether it is beyond pe, with the\nlatter holding a pointer to the end of the buffer. This can lead to\ninformation disclosures or crashes. This function can be triggered via\nuv_getaddrinfo(). (CVE-2021-22918).\n","modified":"2026-01-30T22:18:54.065493Z","published":"2021-07-20T10:46:47Z","related":["CVE-2021-22918"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2021-0360.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=29231"},{"type":"REPORT","url":"https://nodejs.org/en/blog/vulnerability/july-2021-security-releases/"},{"type":"REPORT","url":"https://www.debian.org/security/2021/dsa-4936"},{"type":"REPORT","url":"https://ubuntu.com/security/notices/USN-5007-1"}],"affected":[{"package":{"name":"libuv","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/libuv?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.40.0-1.1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0360.json"}}],"schema_version":"1.7.3","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}