CVE-2023-1255
Node.js vulnerability analysis and mitigation

Overview

The vulnerability (CVE-2023-1255) affects the AES-XTS cipher decryption implementation for 64-bit ARM platforms in OpenSSL. The issue was discovered by Anton Romanov from Amazon and affects OpenSSL versions 3.1.0 prior to 3.1.1 and 3.0.0 prior to 3.0.9. The vulnerability was disclosed and patched in April 2023 (NVD).

Technical details

The vulnerability occurs when processing buffer sizes that are 4 mod 5 during AES-XTS decryption operations on ARM 64-bit platforms. The implementation contains a bug that could cause it to read past the input buffer boundaries. The vulnerability has been assigned a CVSS base score of 5.9 (Medium) with the vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H (NetApp Security).

Impact

If successfully exploited, this vulnerability could trigger a crash of an application using AES-XTS decryption if the memory just after the buffer being decrypted is not mapped. The primary impact is potential Denial of Service (DoS). However, if the memory after the buffer is mapped, the overread is considered harmless (OpenSSL Commit).

Mitigation and workarounds

The vulnerability has been fixed in OpenSSL versions 3.0.9 and 3.1.1. Users are advised to upgrade to these or later versions to address the issue. The fix involves modifying the AES-XTS cipher decryption implementation to prevent buffer overread conditions (OpenSSL Commit).

Additional resources


SourceThis report was generated using AI

Related Node.js vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-64756HIGH7.5
  • JavaScriptJavaScript
  • rhel8::python-39
NoYesNov 17, 2025
CVE-2025-27210HIGH7.5
  • Node.jsNode.js
  • nodejs
NoYesJul 18, 2025
CVE-2025-27209HIGH7.5
  • Node.jsNode.js
  • cpe:2.3:a:nodejs:node.js
NoYesJul 18, 2025
CVE-2025-7458MEDIUM6.9
  • SQLiteSQLite
  • nodejs:22::nodejs-devel
NoYesJul 29, 2025
CVE-2025-52099N/AN/A
  • SQLiteSQLite
  • rust-toolset
NoYesOct 24, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management