Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2025-47153 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

Certain build processes for libuv and Node.js for 32-bit systems, such as for the nodejs binary package through nodejs_20.19.0+dfsg-2_i386.deb for Debian GNU/Linux, have an inconsistent off_t size (e.g., building on i386 Debian always uses _FILE_OFFSET_BITS=64 for the libuv dynamic library, but uses the _FILE_OFFSET_BITS global system default of 32 for nodejs), leading to out-of-bounds access. NOTE: this is not a problem in the Node.js software itself. In particular, the Node.js website's download page does not offer prebuilt Node.js for Linux on i386.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-1102Reliance on Machine-Dependent Data Representation[email protected]

Affected Products

ProductVersions
libuv
>= 1.44.0, < 1.44.2-1 (semver)

CPE

  • cpe:2.3:a:libuv:libuv:*:*:*:*:*:*:*:*
  • cpe:2.3:a:libuv_project:libuv:*:*:*:*:*:*:*:*

Remediation

  • Upgrade: 1.44.2-1moderate effort
Node.js
18.19.0+dfsg-6~deb12u2
20.19.0+dfsg-2 (semver)

CPE

  • cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:*
  • cpe:2.3:a:nodejs:nodejs:*:*:*:*:*:*:*:*

Remediation

  • Upgrade: 20.19.0+dfsg1-1moderate effort
Debian
< 12.22.12~dfsg-1~deb11u7

CPE

  • cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*

Remediation

  • Upgrade: 12.22.12~dfsg-1~deb11u7moderate effort

Change History

7 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2025-47153
NVD Published Date:
May 1, 2025
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]