setuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid(). This allows the process to perform privileged operations despite presumably having dropped such privileges through a call to setuid(). This vulnerability affects all users using version greater or equal than Node.js 18.18.0, Node.js 20.4.0 and Node.js 21.
nodejs Rocky
Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.s390x::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.ppc64le::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.aarch64::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.src::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.x86_64::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.s390x::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.aarch64::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.ppc64le::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.src::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.x86_64::nodejs:20 RHSA-2024:1687 nodejs Red Hat / RHEL
Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.aarch64::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.x86_64::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.s390x::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.ppc64le::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.ppc64le::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.aarch64::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.src::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.s390x::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.src::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.x86_64::nodejs:20 RHSA-2024:1688 nodejs-debuginfo Red Hat / RHEL
Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.ppc64le::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.aarch64::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.s390x::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.x86_64::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.aarch64::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.ppc64le::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.s390x::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.x86_64::nodejs:20 RHSA-2024:1687 nodejs-debuginfo Rocky
Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.aarch64::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.ppc64le::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.s390x::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.x86_64::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.aarch64::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.ppc64le::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.s390x::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.x86_64::nodejs:20 RHSA-2024:1687 nodejs-debugsource Rocky
Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.s390x::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.ppc64le::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.x86_64::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.aarch64::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.ppc64le::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.aarch64::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.s390x::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.x86_64::nodejs:20 RHSA-2024:1687 nodejs-debugsource Red Hat / RHEL
Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.ppc64le::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.s390x::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.s390x::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.x86_64::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.aarch64::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.ppc64le::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.aarch64::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.x86_64::nodejs:20 RHSA-2024:1687 nodejs-devel Rocky
Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.x86_64::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.s390x::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.ppc64le::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.aarch64::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.s390x::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.ppc64le::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.x86_64::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.aarch64::nodejs:20 RHSA-2024:1687 nodejs-devel Red Hat / RHEL
Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.aarch64::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.s390x::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.ppc64le::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.x86_64::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.s390x::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.ppc64le::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.x86_64::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.aarch64::nodejs:20 RHSA-2024:1687 nodejs-docs Red Hat / RHEL
Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.noarch::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.noarch::nodejs:20 RHSA-2024:1687 nodejs-docs Rocky
Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.noarch::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.noarch::nodejs:20 RHSA-2024:1688 nodejs-full-i18n Rocky
Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.x86_64::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.aarch64::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.ppc64le::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.s390x::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.s390x::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.x86_64::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.aarch64::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.ppc64le::nodejs:20 RHSA-2024:1687 nodejs-full-i18n Red Hat / RHEL
Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.ppc64le::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.aarch64::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.ppc64le::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.aarch64::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.s390x::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el8.9.0+21380+12032667.x86_64::nodejs:20 RHSA-2024:1687 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.x86_64::nodejs:20 RHSA-2024:1688 Fixed in: 1:20.11.1-1.module+el9.3.0+21385+bac43d5a.s390x::nodejs:20 RHSA-2024:1688 nodejs-nodemon Red Hat / RHEL
Fixed in: 0:3.0.1-1.module+el8.9.0+20473+c4e3d824.noarch::nodejs:20 RHSA-2024:1687 Fixed in: 0:3.0.1-1.module+el9.3.0.z+20478+84a9f781.noarch::nodejs:20 RHSA-2024:1688 Fixed in: 0:3.0.1-1.module+el8.9.0+20473+c4e3d824.src::nodejs:20 RHSA-2024:1687 Fixed in: 0:3.0.1-1.module+el9.3.0.z+20478+84a9f781.src::nodejs:20 RHSA-2024:1688 nodejs-nodemon Rocky
Fixed in: 0:3.0.1-1.module+el9.3.0.z+20478+84a9f781.src::nodejs:20 RHSA-2024:1688 Fixed in: 0:3.0.1-1.module+el8.9.0+20473+c4e3d824.src::nodejs:20 RHSA-2024:1687 Fixed in: 0:3.0.1-1.module+el9.3.0.z+20478+84a9f781.noarch::nodejs:20 RHSA-2024:1688 Fixed in: 0:3.0.1-1.module+el8.9.0+20473+c4e3d824.noarch::nodejs:20 RHSA-2024:1687 nodejs-packaging Red Hat / RHEL
Fixed in: 0:2021.06-4.module+el9.3.0+19518+63aad52d.src::nodejs:20 RHSA-2024:1688 Fixed in: 0:2021.06-4.module+el8.9.0+19519+e25b965a.src::nodejs:20 RHSA-2024:1687 Fixed in: 0:2021.06-4.module+el8.9.0+19519+e25b965a.noarch::nodejs:20 RHSA-2024:1687 Fixed in: 0:2021.06-4.module+el9.3.0+19518+63aad52d.noarch::nodejs:20 RHSA-2024:1688 nodejs-packaging Rocky
Fixed in: 0:2021.06-4.module+el8.9.0+19519+e25b965a.src::nodejs:20 RHSA-2024:1687 Fixed in: 0:2021.06-4.module+el8.9.0+19519+e25b965a.noarch::nodejs:20 RHSA-2024:1687 Fixed in: 0:2021.06-4.module+el9.3.0+19518+63aad52d.src::nodejs:20 RHSA-2024:1688 Fixed in: 0:2021.06-4.module+el9.3.0+19518+63aad52d.noarch::nodejs:20 RHSA-2024:1688 nodejs-packaging-bundler Red Hat / RHEL
Fixed in: 0:2021.06-4.module+el8.9.0+19519+e25b965a.noarch::nodejs:20 RHSA-2024:1687 Fixed in: 0:2021.06-4.module+el9.3.0+19518+63aad52d.noarch::nodejs:20 RHSA-2024:1688 nodejs-packaging-bundler Rocky
Fixed in: 0:2021.06-4.module+el8.9.0+19519+e25b965a.noarch::nodejs:20 RHSA-2024:1687 Fixed in: 0:2021.06-4.module+el9.3.0+19518+63aad52d.noarch::nodejs:20 RHSA-2024:1688 npm Rocky
Fixed in: 1:10.2.4-1.20.11.1.1.module+el8.9.0+21380+12032667.s390x::nodejs:20 RHSA-2024:1687 Fixed in: 1:10.2.4-1.20.11.1.1.module+el8.9.0+21380+12032667.ppc64le::nodejs:20 RHSA-2024:1687 Fixed in: 1:10.2.4-1.20.11.1.1.module+el8.9.0+21380+12032667.x86_64::nodejs:20 RHSA-2024:1687 Fixed in: 1:10.2.4-1.20.11.1.1.module+el8.9.0+21380+12032667.aarch64::nodejs:20 RHSA-2024:1687 Fixed in: 1:10.2.4-1.20.11.1.1.module+el9.3.0+21385+bac43d5a.ppc64le::nodejs:20 RHSA-2024:1688 Fixed in: 1:10.2.4-1.20.11.1.1.module+el9.3.0+21385+bac43d5a.aarch64::nodejs:20 RHSA-2024:1688 Fixed in: 1:10.2.4-1.20.11.1.1.module+el9.3.0+21385+bac43d5a.x86_64::nodejs:20 RHSA-2024:1688 Fixed in: 1:10.2.4-1.20.11.1.1.module+el9.3.0+21385+bac43d5a.s390x::nodejs:20 RHSA-2024:1688 npm Red Hat / RHEL
Fixed in: 1:10.2.4-1.20.11.1.1.module+el9.3.0+21385+bac43d5a.s390x::nodejs:20 RHSA-2024:1688 Fixed in: 1:10.2.4-1.20.11.1.1.module+el9.3.0+21385+bac43d5a.ppc64le::nodejs:20 RHSA-2024:1688 Fixed in: 1:10.2.4-1.20.11.1.1.module+el9.3.0+21385+bac43d5a.x86_64::nodejs:20 RHSA-2024:1688 Fixed in: 1:10.2.4-1.20.11.1.1.module+el8.9.0+21380+12032667.ppc64le::nodejs:20 RHSA-2024:1687 Fixed in: 1:10.2.4-1.20.11.1.1.module+el8.9.0+21380+12032667.x86_64::nodejs:20 RHSA-2024:1687 Fixed in: 1:10.2.4-1.20.11.1.1.module+el8.9.0+21380+12032667.s390x::nodejs:20 RHSA-2024:1687 Fixed in: 1:10.2.4-1.20.11.1.1.module+el9.3.0+21385+bac43d5a.aarch64::nodejs:20 RHSA-2024:1688 Fixed in: 1:10.2.4-1.20.11.1.1.module+el8.9.0+21380+12032667.aarch64::nodejs:20 RHSA-2024:1687 TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works
Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.
Exploitability
Attack Vector Local
Attack Complexity Low
Privileges Required High
User Interaction None
Scope Changed
Impact
Confidentiality Low
Integrity High
Availability Low
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:L
0.89% probability of exploitation in 30 days
55th percentile
Moderate risk: more likely to be exploited than 55% of all known CVEs.
Other CWE-250 vulnerabilities, ordered by exploit likelihood. View all
Embed a live status badge for CVE-2024-22017 Markdown
[](https://tridentstack.com/cve/CVE-2024-22017)HTML
<a href="https://tridentstack.com/cve/CVE-2024-22017"><img src="https://tridentstack.com/cve/badge/CVE-2024-22017.svg" alt="CVE-2024-22017"></a>Find and fix vulnerabilities across your fleet TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.
This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2024-11-21.