Junglewise Threat Intelligence

CVE-2022-24373: Software Mansion react-native-reanimated ReDoS in Colors.js

CVE-2022-24373 · Severity: low · CVSS 3.1 · Published 2022-10-01

Vendors: npm.

Executive brief

A vulnerability in the react-native-reanimated library, which is used to create smooth animations in mobile applications, could allow an attacker to crash an app or make it unresponsive. By providing a specially crafted color string, an attacker can trigger a process that consumes excessive CPU resources. This results in a denial-of-service condition, affecting the application's availability for users.

Technical details

The react-native-reanimated library before versions 2.10.0 and 3.0.0-rc.1 contains a Regular Expression Denial of Service (ReDoS) vulnerability. The flaw exists in the `Colors.js` component due to an inefficient regular expression used to parse numeric values within color strings. An attacker who can control the color input passed to the library can provide a maliciously crafted string that triggers catastrophic backtracking in the regex engine. This leads to 100% CPU utilization and a denial-of-service (DoS) condition. The issue was resolved by optimizing the regular expression to ensure linear processing time.

Affected products

  • software-mansion react-native-reanimated < 2.10.0, < 3.0.0-rc.1

Timeline

  • 2022-07-12: disclosed: Initial pull request describing the ReDoS vulnerability submitted.
  • 2022-07-25: patched: Fix merged into the main branch.
  • 2022-09-30: advisory: NVD publication date.
  • 2022-10-01: advisory: GitHub Advisory published.

References