The vendor explicitly states that these products are not affected by this CVE.
- libuv-devel as a component of Red Hat Enterprise Linux 10
- libuv-static as a component of Red Hat Enterprise Linux 10
- libuv.src as a component of Red Hat Enterprise Linux 10
- nodejs as a component of Red Hat Enterprise Linux 10
- nodejs-devel as a component of Red Hat Enterprise Linux 10
- nodejs-docs as a component of Red Hat Enterprise Linux 10
- nodejs-full-i18n as a component of Red Hat Enterprise Linux 10
- nodejs-libs as a component of Red Hat Enterprise Linux 10
- nodejs-npm as a component of Red Hat Enterprise Linux 10
- nodejs22.src as a component of Red Hat Enterprise Linux 10
- libuv as a component of Red Hat Enterprise Linux 8
- libuv-devel as a component of Red Hat Enterprise Linux 8
- Summary
- A flaw was found in the build process of libuv and Node.js on 32-bit systems. This vulnerability allows out-of-bounds memory access via mismatched _FILE_OFFSET_BITS settings during compilation, where libuv is built with 64-bit file offsets and Node.js with 32-bit defaults.
- Remediation
- No remediation text is recorded.
