We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-27934

*const c_void / ExternalPointer unsoundness leading to use-after-free



AssignerGitHub_M
Reserved2024-02-28
Published2024-03-06
Updated2024-08-02

Description

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.36.2 and prior to version 1.40.3, use of inherently unsafe `*const c_void` and `ExternalPointer` leads to use-after-free access of the underlying structure, resulting in arbitrary code execution. Use of inherently unsafe `*const c_void` and `ExternalPointer` leads to use-after-free access of the underlying structure, which is exploitable by an attacker controlling the code executed inside a Deno runtime to obtain arbitrary code execution on the host machine regardless of permissions. This bug is known to be exploitable for both `*const c_void` and `ExternalPointer` implementations. Version 1.40.3 fixes this issue.



HIGH: 8.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Product status

>= 1.36.2, < 1.40.3
affected

References

https://github.com/denoland/deno/security/advisories/GHSA-3j27-563v-28wf

cve.org CVE-2024-27934

nvd.nist.gov CVE-2024-27934

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-27934
Subscribe to our newsletter to learn more about our work.