---
id: CVE-2018-7167
title: >-
  Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a
  hang which could result in a Denial of Service
summary: >-
  Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a
  hang which could result in a Denial of Service. In order to address this
  vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were
  updated so th…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-119
vendor: nodejs
product: node.js
affected:
  - 'node.js > 6.9.0, < 6.14.3'
  - 'node.js >= 8.9.0, < 8.11.3'
  - 'node.js >= 9.0.0, < 9.11.2'
patched:
  - node.js 9.11.2
published: '2018-06-13'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:16:48.373'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-7167'
references:
  - url: 'http://www.securityfocus.com/bid/106363'
    label: cve-request@iojs.org
  - url: 'https://nodejs.org/en/blog/vulnerability/june-2018-security-releases/'
    label: cve-request@iojs.org
  - url: 'https://security.gentoo.org/glsa/202003-48'
    label: cve-request@iojs.org
  - url: 'http://www.securityfocus.com/bid/106363'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://nodejs.org/en/blog/vulnerability/june-2018-security-releases/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202003-48'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.07123
epssPercentile: 0.94098
ingestedAt: '2026-10-08T23:16:47.291Z'
---

## Overview

Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS "Boron"), 8.x (LTS "Carbon"), and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable.

## Affected

- `node.js > 6.9.0, < 6.14.3`
- `node.js >= 8.9.0, < 8.11.3`
- `node.js >= 9.0.0, < 9.11.2`

## Remediation

Upgrade past the affected range:

- `node.js 9.11.2`
