GHSA-c25x-cm9x-qqgx
Deno improperly handles resizable ArrayBuffer
Details
### Impact
[Resizable ArrayBuffers](https://github.com/tc39/proposal-resizablearraybuffer) passed to asynchronous native functions that are shrunk during the asynchronous operation could result in an out-of-bound read/write.
It is unlikely that this has been exploited in the wild, as the only version affected is Deno 1.32.0.
Deno Deploy users are not affected.
### Patches
The problem has been resolved by disabling resizable ArrayBuffers temporarily in Deno 1.32.1. A future version of Deno will re-enable resizable ArrayBuffers with a proper fix.
### Workarounds
Upgrade to Deno 1.32.1, or run with `--v8-flags=--no-harmony-rab-gsab` to disable resizable ArrayBuffers.
Are you affected?
Enter the version of the package you're using.
Affected packages
1.32.0Fixed in: 1.32.1Upgrade Deno to 1.32.1 or newer (ecosystem crates.io).
0.87.0Fixed in: 0.88.0Upgrade serde_v8 to 0.88.0 or newer (ecosystem crates.io).
0.102.0Fixed in: 0.103.0Upgrade deno_runtime to 0.103.0 or newer (ecosystem crates.io).
References
- https://github.com/denoland/deno/security/advisories/GHSA-c25x-cm9x-qqgx[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-28445[ADVISORY]
- https://github.com/denoland/deno/pull/18395[WEB]
- https://github.com/denoland/deno/pull/18452[WEB]
- https://github.com/denoland/deno[PACKAGE]
- https://github.com/denoland/deno/releases/tag/v1.32.1[WEB]