nodejs / nodejs/node

`net.Socket({ fd })` can abort the Node.js process when iterating invalid file descriptors

Open
#63,308 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

stale
Dominant language
JavaScript
Stars
122k
Forks
37.3k
Avg merge
4d 2h
Merged PRs (30d)
283

Description

Version

24.13.1

Platform
Linux KContainer 6.12.86+deb13-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.12.86-1 (2026-05-08) x86_64 x86_64 x86_64 GNU/Linux
Subsystem

net

What steps will reproduce the bug?

Hi,

I found a case where creating net.Socket instances with arbitrary file descriptors can abort the entire Node.js process.

const net = require('net');

let fd = 3;
while (fd < 1000) {
  try {
    const stream = new net.Socket({
      fd: fd,
      readable: false,
      writable: true
    });
    stream.on('error', function () {});
    stream.write('might crash');
  } catch (e) {
    // ignore and continue to next fd
    console.log('caught')
  }
  fd += 1;
}
How often does it reproduce? Is there a required condition?

Reproduces consistently on my system.

What is the expected behavior? Why is that the expected behavior?

Invalid or unsupported file descriptors passed to net.Socket({ fd }) should result in ordinary JS exceptions or socket errors, not process abort.

What do you see instead?

Some file descriptors are handled normally and throw JS exceptions that are caught successfully, but eventually Node aborts the process:

root@KContainer:~/git/run/cerebras/node/OPENAI/gpt5.1/filter/batch_3/cross_runtime/temp_deno/3604# node repro.cjs caught caught caught caught 
caught 
caught 
.... 
caught 
caught 
caught 
caught 
caught 
caught 
caught 
caught
Aborted

The abort bypasses JS exception handling entirely.

Additional information

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the provided JavaScript reproduction and the net.Socket({ fd }) path on Linux, focusing on how invalid descriptors are handled before stream.write(). Confirm the abort is reproducible, then verify that invalid or unsupported descriptors produce catchable JavaScript exceptions or socket errors without terminating the process.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, node.js
Domain
networking
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.