There was a missing check for negative parameter value in Buffer() and Buffer.allocUnsafe(). When user input is passed unchecked to the Buffer constructor or allocUnsafe(), it can expose parts of the memory slab used by other Buffers in the application. External Reference: https://nodejs.org/en/blog/release/v6.2.1/ Upstream patch: https://github.com/nodejs/node/pull/7051
Created nodejs tracking bugs for this issue: Affects: fedora-all [bug 1343395] Affects: epel-all [bug 1343396]
Openshift Enterprise references the latest RHSCL image, which contains 4.6.2. Marking as not affected. https://github.com/openshift/library/blob/master/official/nodejs/imagestreams/nodejs-rhel7.json