PT-2026-94332 · Npm · Vm2
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
vm2 versions prior to 3.11.6
Description
Failure to enforce the
bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray constructors allows attackers to allocate arbitrary host memory. While the bufferAllocLimit defense caps Buffer.alloc, Buffer.allocUnsafe, Buffer.allocUnsafeSlow, and new Buffer(N), it does not intercept V8 intrinsics such as Uint8Array or Float64Array. These constructors utilize the same underlying C++ allocation path as Buffer.alloc but bypass the size cap, enabling an attacker to exhaust host process memory and trigger out-of-memory (OOM) conditions. This can lead to a complete denial of service, particularly in memory-constrained environments like Docker containers, Kubernetes pods, and AWS Lambda.Recommendations
Update vm2 to version 3.11.6 or later.
As a temporary workaround, restrict the use of
ArrayBuffer, SharedArrayBuffer, and TypedArray constructors within the sandbox until the update is applied.Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vm2