CVE-2023-46809

Publication date 7 September 2024

Last updated 11 September 2024


Ubuntu priority

Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - https://people.redhat.com/~hkario/marvin/, if PCKS #1 v1.5 padding is allowed when performing RSA descryption using a private key.

Read the notes from the security team

Status

Package Ubuntu Release Status
nodejs 24.10 oracular
Not affected
24.04 LTS noble
Needs evaluation
23.10 mantic Ignored end of life, was needs-triage
22.04 LTS jammy
Needs evaluation
20.04 LTS focal
Needs evaluation
18.04 LTS bionic
Needs evaluation
16.04 LTS xenial
Needs evaluation
14.04 LTS trusty Ignored end of ESM support, was needs-triage

Notes


eslerm

Reserved But Public (RBP) CVE. Asking CNA to publish.