CVE-2025-47153

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-47153
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-47153.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-47153
Downstream
Published
2025-05-01T07:15:58Z
Modified
2025-08-29T19:01:37Z
Summary
[none]
Details

Certain build processes for libuv and Node.js for 32-bit systems, such as for the nodejs binary package through nodejs20.19.0+dfsg-2i386.deb for Debian GNU/Linux, have an inconsistent offt size (e.g., building on i386 Debian always uses _FILEOFFSETBITS=64 for the libuv dynamic library, but uses the _FILEOFFSET_BITS global system default of 32 for nodejs), leading to out-of-bounds access. NOTE: this is not a problem in the Node.js software itself. In particular, the Node.js website's download page does not offer prebuilt Node.js for Linux on i386.

References

Affected packages