Skip to content

Possible wrong CVE-2021-22930 reference (should be CVE-2021-22940) in tagged v16.6.2 / v14.17.5 releases #40306

Closed
@cfi-gb

Description

@cfi-gb

As this is affecting this repository / the tagged releases of this repo i hope this is the correct place to report this problem, if not please let me know where to forward the following below.

On the following tags:

as well as in the related CHANGELOG_v14.md / CHANGELOG_v16.md the following is stated for the mentioned releases:

CVE-2021-22930: Use after free on close http2 on stream canceling (High)

Comparing the releases with the announcement here:

https://nodejs.org/en/blog/vulnerability/aug-2021-security-releases/

this probably should be the following instead:

CVE-2021-22940 Use after free on close http2 on stream canceling (High)

due to:

The issue is a follow on to CVE-2021-22930 as the issue was not completely resolved in the fix for CVE-2021-22930.

Metadata

Metadata

Assignees

No one assigned

    Labels

    docIssues and PRs related to the documentations.securityIssues and PRs related to security.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions