Skip to content

[Vulnerability] nodejs/node: Integer Overflow / Division by Zero #88

Description

@github-actions

Potential Security Vulnerability Detected

Repository: nodejs/node
Commit: 7547e79
Author: Node.js GitHub Bot
Date: 2026-03-20T17:25:46Z

Commit Message

deps: update icu to 78.3

PR-URL: https://github.com/nodejs/node/pull/62324
Reviewed-By: Richard Lau <richard.lau@ibm.com>
Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>

Pull Request

PR: #62324 - deps: update icu to 78.3
Labels: test, tools, i18n-api, author ready, needs-ci, dependencies, icu, lts-watch-v22.x, lts-watch-v24.x

Description:
This is an[ automated update](https://github.com/nodejs/node/actions/runs/23257091672/job/67615018642) of icu to 78.3.

Analysis

Vulnerability Type: Integer Overflow / Division by Zero
Severity: Medium

Description

The patch fixes ICU-23109 in nfrule.cpp where util64_pow(rule1-&gt;radix, rule1-&gt;exponent) could overflow to zero, causing a subsequent modulo-by-zero operation (rule1-&gt;baseValue % util64_pow(rule1-&gt;radix, rule1-&gt;exponent)). While there was already a comment about preventing % 0, the existing check rule1-&gt;radix != 0 did not guard against the case where the power computation itself overflows to zero. The patch introduces a pre-computed mod variable with an explicit overflow check, returning an error status if mod is zero.

Affected Code

if ((rule1->baseValue > 0
    && (rule1->radix != 0) // ICU-23109 Ensure next line won't "% 0"
    && (rule1->baseValue % util64_pow(rule1->radix, rule1->exponent)) == 0)

Proof of Concept

Construct an ICU RuleBasedNumberFormat rule with a large radix and exponent such that util64_pow(radix, exponent) overflows uint64_t to 0, e.g., radix=10, exponent=20+ causes overflow. This triggers division-by-zero in the modulo operation `rule1->baseValue % 0`, which is undefined behavior in C++ and can cause a crash (SIGFPE or abort) when parsing/formatting numbers with such rules in Node.js via the Intl API.

This issue was automatically created by Vulnerability Spoiler Alert.
Detected at: 2026-03-20T17:43:15.359Z

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions