
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-47153 affects Node.js on 32-bit systems due to an inconsistent off_t size configuration between libuv and Node.js builds. The vulnerability was discovered in May 2025 and affects nodejs binary packages through nodejs_20.19.0+dfsg-2_i386.deb for Debian GNU/Linux. This issue stems from build processes where libuv uses _FILE_OFFSET_BITS=64 while Node.js uses the system default of 32, leading to potential out-of-bounds access. Notably, this is not a problem in the Node.js software itself, as the Node.js website does not offer prebuilt Node.js for Linux on i386 (NVD, Debian LTS).
The vulnerability arises from inconsistent FILEOFFSETBITS settings between libuv and Node.js builds on 32-bit systems. On i386 Debian systems, libuv is built with FILEOFFSETBITS=64 while Node.js uses the system default of 32, resulting in mismatched struct sizes. The vulnerability has been assigned a CVSS v3.1 Base Score of 6.5 (Medium) with vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L (NVD).
The inconsistent off_t size between libuv and Node.js builds can result in out-of-bounds access, potentially leading to memory corruption and application crashes. This affects various Node.js applications and packages that rely on file system operations on 32-bit systems (Wiz).
The vulnerability requires specific conditions to be exploited, namely the use of Node.js on 32-bit systems with mismatched _FILE_OFFSET_BITS configurations. The CVSS score of 6.5 (Medium) indicates moderate exploitability with network vector but high attack complexity (NVD).
Debian has released security updates to address this vulnerability in version nodejs_20.19.0+dfsg1-1. Several dependent packages were also rebuilt to fix the vulnerability, including node-expat, node-iconv, node-leveldown, and others. Users are recommended to upgrade their nodejs packages to the latest version (Debian LTS).
The vulnerability has sparked discussions about the challenges of maintaining 32-bit support in modern software. Alan Coopersmith from Oracle noted that this issue highlights potential similar problems that might arise with TIMEBITS mismatches as 32-bit builders prepare for the year 2038 (Openwall).
Fix availability across major Linux distributions and their releases.
bookworm
nodejs: 18.20.4+dfsg-1~deb12u1
sid
nodejs: 20.19.0+dfsg1-1
trixie
nodejs: 20.19.0+dfsg1-1
bionic (esm-apps)
nodejs
devel
nodejs
focal (esm-apps)
nodejs
jammy
nodejs
jammy (esm-apps)
nodejs
noble
nodejs
noble (esm-apps)
nodejs
resolute
nodejs
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."