Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-35886.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-35886
Upstream
  • CVE-2024-22017
Published
2024-03-19T05:15:10Z
Modified
2026-04-21T04:25:12.822620Z
Summary
CVE-2024-22017 affecting package libuv for versions less than 1.48.0-1
Details

setuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid(). This allows the process to perform privileged operations despite presumably having dropped such privileges through a call to setuid(). This vulnerability affects all users using version greater or equal than Node.js 18.18.0, Node.js 20.4.0 and Node.js 21.

References

Affected packages

Azure Linux:3 / libuv

Package

Name
libuv
Purl
pkg:rpm/azure-linux/libuv

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.48.0-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-35886.json"