CVE-2015-0278

critical
Published 2015-05-18 · Modified 2026-05-06
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/libuv/libuv/commit/66ab38918c911bcff025562cf06237d7fedaba0c

OS impact

OSVersionStatusFixed in
fedora fedora21affected

Application impact

VendorProductVersionsFixed
libuv_projectlibuv{"endIncluding":"0.10.33"}
nodejsnode.js{"endExcluding":"0.10.37"}0.10.37

References

CWEs

CWE-273

Verify integrity in audit chain (admin only). AS-IS.