Deno improperly handles resizable ArrayBuffer
CVE-2023-28445
What is CVE-2023-28445?
A vulnerability in the Deno Runtime, specifically affecting version 1.32.0, arises from the use of resizable ArrayBuffers in asynchronous functions. When these ArrayBuffers are shrunk during an asynchronous operation, it can lead to out-of-bounds read/write scenarios, posing potential risks to application integrity. Users of Deno Deploy remain unaffected by this issue. In response, Deno version 1.32.1 disables the problematic feature as a temporary measure, while version 1.32.2 aims to reintroduce resizable ArrayBuffers with a proper fix. For urgent implementations, users can run Deno with the flag '--v8-flags=--no-harmony-rab-gsab' to mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
deno = 1.32.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
