-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 24 Mar 2026 22:11:25 +0100 Source: nodejs Binary: libnode-dev libnode115 libnode115-dbgsym nodejs nodejs-dbgsym Architecture: arm64 Version: 20.19.2+dfsg-1+deb13u2 Distribution: trixie-security Urgency: medium Maintainer: arm Build Daemon (arm-conova-04) Changed-By: Jérémy Lal Description: libnode-dev - evented I/O for V8 javascript (development files) libnode115 - evented I/O for V8 javascript - runtime library nodejs - evented I/O for V8 javascript - runtime executable Changes: nodejs (20.19.2+dfsg-1+deb13u2) trixie-security; urgency=medium . * Upstream security patches: + CVE-2026-21713: use timing-safe comparison in Web Cryptography HMAC + CVE-2026-21717: fix array index hash collision + CVE-2026-21710: http: use null prototype for headersDistinct/trailersDistinct + CVE-2026-21716: include permission check on lib/fs/promises + CVE-2026-21715: add permission check to realpath.native + CVE-2026-21714: handle NGHTTP2_ERR_FLOW_CONTROL error code + CVE-2026-21637: tls wrap SNICallback invocation in try/catch * copyright: add rapidhash from sec/51 patch Checksums-Sha1: 1bc4d7b5d121727fc71ef5358e61a03e5f174511 536872 libnode-dev_20.19.2+dfsg-1+deb13u2_arm64.deb dc3d864915064881b9b0b25dd42b4763aa9a15cd 1051736704 libnode115-dbgsym_20.19.2+dfsg-1+deb13u2_arm64.deb 9adcc3351ffcd82cf92c2a00ff7449938afdf665 10900092 libnode115_20.19.2+dfsg-1+deb13u2_arm64.deb 434db85ac731615db11fbc610801d341c0d141a0 82688 nodejs-dbgsym_20.19.2+dfsg-1+deb13u2_arm64.deb 362ae02804c44994a108c65f91c05adf0a870d88 10918 nodejs_20.19.2+dfsg-1+deb13u2_arm64-buildd.buildinfo 987db8ab2f7d326a76362af94eee9d23f0b97336 353548 nodejs_20.19.2+dfsg-1+deb13u2_arm64.deb Checksums-Sha256: 01c93c924cfe7ea1a90a144606d13225dda57763e3b568587b717caee72c58ec 536872 libnode-dev_20.19.2+dfsg-1+deb13u2_arm64.deb 34b54cda4e5da5e620601a57301ded194cc958699bb7b09e56b7d6893d4e0ad6 1051736704 libnode115-dbgsym_20.19.2+dfsg-1+deb13u2_arm64.deb 6841ad1527feca076ab64cff2d4f9e3ed9827393f9b2d55c49709af2d3475448 10900092 libnode115_20.19.2+dfsg-1+deb13u2_arm64.deb 08cbf88b58fdea0ea162f4ccd43787ccf33e3e427179eb6c3d2cee4710a870f5 82688 nodejs-dbgsym_20.19.2+dfsg-1+deb13u2_arm64.deb 3c425924e7e5fe1e329a6e8b1144561763819d76c3e03f1846e0972279ab7336 10918 nodejs_20.19.2+dfsg-1+deb13u2_arm64-buildd.buildinfo 0d8c7a76e091b8bcc2485b3e757e550743c93445d89209d15764f8f71ffcc3df 353548 nodejs_20.19.2+dfsg-1+deb13u2_arm64.deb Files: 21701b04340b32d6d33b4ae9c90e3d7a 536872 libdevel optional libnode-dev_20.19.2+dfsg-1+deb13u2_arm64.deb 9039154f905100ef74b798e157c520f4 1051736704 debug optional libnode115-dbgsym_20.19.2+dfsg-1+deb13u2_arm64.deb eb4500441622738907c6552030b112b0 10900092 libs optional libnode115_20.19.2+dfsg-1+deb13u2_arm64.deb 5fb7554c826d09fe312d6acad5eb26e4 82688 debug optional nodejs-dbgsym_20.19.2+dfsg-1+deb13u2_arm64.deb 71f9d67d2dbf216603a51deefe79e7e3 10918 javascript optional nodejs_20.19.2+dfsg-1+deb13u2_arm64-buildd.buildinfo 7296afd05568022ee7374b98ce6b609d 353548 javascript optional nodejs_20.19.2+dfsg-1+deb13u2_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYxmcRLDHP0tCCM0oScpU3dYulLgFAmnET4sACgkQScpU3dYu lLiUKBAAtkWAmp+tNczZxxU/ynzCxbzqYgT1LdJNhVBVuQTkBBgNe49vz1CPSsgP EgEMYo/5qfSP1y81pmqV0XUMZn3nOxm+v8WLqQQIQ7+MBSXsmSZNvOJG0XHxoFZK X1jy+zmaBtrAtzpFvEIc6gWni20DU0c7SF3RTwYuqkS1s5CS2oSD5bOQoTx4oRU1 im4nXqceAsGMqoW0Q40hlz61V/Mfn2i9ZKpwwLry6mW7JRljuhJtp9XoQ3wZjJcb CeFEOIwsRqtgKER/ppMwp1FDp5Vjt1Md9Jw2ebgSH6qeOlNqt00As45F0qXH/NbM 2Wj2KJom3JjZB/ykKk+bPNRc2IYMW28MbkBmq/gB+4mWRSBPW8hgfsYPKjsSfG+W PD9kIxyrwRZcCwKWzVRLVGInbj+N+XDKjSS27qJ4wQ2yqd7//NzOUyIikF4BDDTr KIrZU4M1bjnsJIGFTwx/JDla0ijKoHWFAwmQFRytGL9G3yLqHf8sQcAZC+aQjVGv Itkdskq41J30y2YD8P1I0M398bA/VuArC4A2rrgTyHX0DNTMJisQtXVIhEJnaOEi hWYdXj5fI7FpFeB2uU3MiYZ+uG4Je1FRPGPf3n6Th5ZeCeq5J3uoonzN1LxLFCvK ZpJkKWXB81mKdYxNqBWwZC8M0boaDw6eTp6omf8pmYx8LKNVC9M= =RR0+ -----END PGP SIGNATURE-----