Junglewise Threat Intelligence

CVE-2022-21164: Venemo node-lmdb denial of service in putString

CVE-2022-21164 · Severity: low · CVSS 3.1 · Published 2022-03-17

Vendors: npm.

Executive brief

node-lmdb is a Node.js library used to interact with the LMDB high-performance database. A vulnerability in how the library handles certain data types can allow an attacker to crash the application, leading to a denial of service. This could disrupt business operations by making database-dependent services unavailable.

Technical details

The node-lmdb package before version 0.9.7 is vulnerable to a Denial of Service (DoS) due to an unhandled case during type checking in the `TxnWrap::putString` method. Specifically, when the library expects a string but receives a value with a non-invokable or invalid `ToString` representation, it fails to validate the input type before processing. An attacker can exploit this by providing a non-string value to the affected method, causing the Node.js process to crash. The fix, introduced in version 0.9.7, adds an explicit check using `info[2]->IsString()` to ensure the input is a valid string before proceeding.

Affected products

  • Venemo node-lmdb < 0.9.7

Timeline

  • 2022-03-16: advisory: NVD publication date
  • 2022-03-17: disclosed: GitHub Advisory published
  • 2022-03-19: patched: GitHub reviewed the advisory and confirmed the fix in 0.9.7

References