Intel

AIKIDO-2024-10227

@cloudflare/workerd-linux-64 is vulnerable to Race Condition

Race Condition Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Aug 22, 2024

44

Medium Risk

This Affects:

js@cloudflare/workerd-linux-64
1.20221108.0 - 1.20240815.0
Fixed in 1.20240821.0
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'). The fixed version solves several potential race conditions in security related code, which could have lead to unwanted behaviour or errors.

Who does this affect?

You're affected if you are using a version which is within vulnerability ranges.

Background info

@cloudflare/workerd-linux-64 is vulnerable to Race Condition in versions 1.20221108.0 - 1.20240815.0.

How to fix this

Upgrade @cloudflare/workerd-linux-64 library to patch version.