-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 24 Mar 2026 22:11:25 +0100 Source: nodejs Binary: libnode-dev libnode115 libnode115-dbgsym nodejs nodejs-dbgsym Architecture: armhf Version: 20.19.2+dfsg-1+deb13u2 Distribution: trixie-security Urgency: medium Maintainer: arm Build Daemon (arm-conova-01) Changed-By: Jérémy Lal Description: libnode-dev - evented I/O for V8 javascript (development files) libnode115 - evented I/O for V8 javascript - runtime library nodejs - evented I/O for V8 javascript - runtime executable Changes: nodejs (20.19.2+dfsg-1+deb13u2) trixie-security; urgency=medium . * Upstream security patches: + CVE-2026-21713: use timing-safe comparison in Web Cryptography HMAC + CVE-2026-21717: fix array index hash collision + CVE-2026-21710: http: use null prototype for headersDistinct/trailersDistinct + CVE-2026-21716: include permission check on lib/fs/promises + CVE-2026-21715: add permission check to realpath.native + CVE-2026-21714: handle NGHTTP2_ERR_FLOW_CONTROL error code + CVE-2026-21637: tls wrap SNICallback invocation in try/catch * copyright: add rapidhash from sec/51 patch Checksums-Sha1: 44f475e2864c313c9c47dfecc5495bc9a4171c5c 536924 libnode-dev_20.19.2+dfsg-1+deb13u2_armhf.deb 92166b55de178cb1606721a35facd75fc6aae5ad 39160264 libnode115-dbgsym_20.19.2+dfsg-1+deb13u2_armhf.deb d362681e20ecc04c93a601d8759e4b23c6b11976 10232160 libnode115_20.19.2+dfsg-1+deb13u2_armhf.deb f29b9c50188ed9bc6ffcb502b6bc6ba7801219ee 3260 nodejs-dbgsym_20.19.2+dfsg-1+deb13u2_armhf.deb e834afb06a6825730c92d69315c63db4804f2416 10788 nodejs_20.19.2+dfsg-1+deb13u2_armhf-buildd.buildinfo f62f54d26f0c5cdf67618d36f710e7a28a7018c1 353480 nodejs_20.19.2+dfsg-1+deb13u2_armhf.deb Checksums-Sha256: f4268881564fecc1848ee59cc902026b7b1bc236a201d441bca669778946f094 536924 libnode-dev_20.19.2+dfsg-1+deb13u2_armhf.deb 14a5a7a0d244f0ca09adbe5e98d76d2568cd8d6b1e635dae49a96ac5cdaf90ba 39160264 libnode115-dbgsym_20.19.2+dfsg-1+deb13u2_armhf.deb b2cdbaefbeb13beb30b294805b12f78f291b0e4271ec515c9eeda638fe9bc2d1 10232160 libnode115_20.19.2+dfsg-1+deb13u2_armhf.deb 638feee8712a1d2d3a1b876b5415e7d77a0096a094ae80dcbb0b18e5a95bfe33 3260 nodejs-dbgsym_20.19.2+dfsg-1+deb13u2_armhf.deb 30746708a834d29bf57bdaf40b0ba174c045f5c5338f9df3adf7627b11ee5855 10788 nodejs_20.19.2+dfsg-1+deb13u2_armhf-buildd.buildinfo 5a5eaa4e56bf145f393f5d02f0027f4965989447a3b78e081f7109b409ab2c0b 353480 nodejs_20.19.2+dfsg-1+deb13u2_armhf.deb Files: 3771c8935e561baec8b04388f5d1eb84 536924 libdevel optional libnode-dev_20.19.2+dfsg-1+deb13u2_armhf.deb ee2430f29173fd6472859b27c1a0c8fd 39160264 debug optional libnode115-dbgsym_20.19.2+dfsg-1+deb13u2_armhf.deb 67d2a9f5a03c87c2750f8ba3ee9a8617 10232160 libs optional libnode115_20.19.2+dfsg-1+deb13u2_armhf.deb 4473d8724d2d582090b60a37e8637e71 3260 debug optional nodejs-dbgsym_20.19.2+dfsg-1+deb13u2_armhf.deb 90b4b885892a16b283dde8f0de4cbf40 10788 javascript optional nodejs_20.19.2+dfsg-1+deb13u2_armhf-buildd.buildinfo 5ccf3ad5c25483cad58771fef48ff79e 353480 javascript optional nodejs_20.19.2+dfsg-1+deb13u2_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEO4qAQUSIo2p/kVRf8U6eOZMpj68FAmnEj5wACgkQ8U6eOZMp j6963w/6A9s56vl/ee+QsYBDgd9FjAqe4QOdpB4qi52uEPDDdUDsTb8wRDmMOzhu TR5DCxXjxfbN18CBdYP8S0rKOTHMtjCblcrdmDvfmatSZ+W3RM9NGY7ype/QZ8j/ bthVud18+HTQdz9O5g1vXyoHT62W/unmfO7HLtGpbnTn5LqpB54OqHM5QA+hoUg+ /HHK4RN+DhM+kMOPrnnCma4qwllVf9H94XsiW5mofmI0Gf6lqmv0i6wBgybCeTJe 3PBENWFb+Pame1gCr6qTc7XRuNRmvDiGohrrq3JfpTBiVanxXAq+rdLYVgQ2kfXf 0lXcqHSKehoZRlDrh8MATExKpbulC65qTNGuweINjpq3T0CoZhDUjNHVs9oEhC3u tqF0had+RvdH3Id7mJhnkhHOLnRQvpnjB8U6Hm5JfiCKtrmuPMCCRKLBzUnFqyZ0 HlQ3vA7kiWWVrmbJwEA7cOuZ26Ygxmvt+DIzWOBCrZILlKig47krTISjsgdOgHBJ KJmyDIdc0Aatp6m93QunED0adTSsyM1IrTWmPW80id6yD1yiv4rCom0veRSHI72+ Y69y+nSj3BaYJ8W7+82/nXJ1Rrr5NHJMf1/e6fe5APA+cQMYGS7ZyC5weNMM14j1 ZKzxnxxBTpwhnji4psvqPnSzR0LBhX4b+DIOnRGT/FM2xglVf8Y= =96UZ -----END PGP SIGNATURE-----