libuv's realpath() implementation performs an incorrect calculation when allocating a buffer, leading to a potential buffer overflow. Upstream advisory: https://nodejs.org/en/blog/vulnerability/september-2020-security-releases/
Upstream MR: https://github.com/libuv/libuv/pull/2966 Introduced in commit: https://github.com/libuv/libuv/commit/b56d279b172fbe78dee2fb1d29cae9c9c5c6d1c4
Introduced in upstream release 1.24.0
Created nodejs tracking bugs for this issue: Affects: epel-all [bug 1879335] Affects: fedora-all [bug 1879336] Created nodejs:11/nodejs tracking bugs for this issue: Affects: fedora-all [bug 1879337] Created nodejs:12/nodejs tracking bugs for this issue: Affects: fedora-all [bug 1879338] Created nodejs:13/nodejs tracking bugs for this issue: Affects: fedora-all [bug 1879339] Created nodejs:14/nodejs tracking bugs for this issue: Affects: fedora-all [bug 1879342]
Statement: As shipped in Red Hat Software Collections (nodejs-10 & nodejs-12) as well as Red Hat Enterprise Linux 8 (nodejs-10 and nodejs-12), no incorrect use of the `UV__PATH_MAX` macro were found. Although the releases of libuv contained in these versions of nodejs are considered "Affected", it is considered not feasible to trigger the flaw. NodeJS is included in Red Hat Quay as a dependency of Yarn which is only used while building Red Hat Quay, and not during runtime. Red Hat Enterprise Linux 8 ships libuv-1.23.1, which is not vulnerable to this flaw.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:4272 https://access.redhat.com/errata/RHSA-2020:4272
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-8252
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.1 Extended Update Support Via RHSA-2020:4903 https://access.redhat.com/errata/RHSA-2020:4903
This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS Via RHSA-2020:5086 https://access.redhat.com/errata/RHSA-2020:5086
This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS Via RHSA-2021:0521 https://access.redhat.com/errata/RHSA-2021:0521
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:0548 https://access.redhat.com/errata/RHSA-2021:0548