-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 24 Mar 2026 22:11:25 +0100 Source: nodejs Binary: libnode-dev libnode115 libnode115-dbgsym nodejs nodejs-dbgsym Architecture: riscv64 Version: 20.19.2+dfsg-1+deb13u2 Distribution: trixie-security Urgency: medium Maintainer: riscv64 Build Daemon (rv-osuosl-02) Changed-By: Jérémy Lal Description: libnode-dev - evented I/O for V8 javascript (development files) libnode115 - evented I/O for V8 javascript - runtime library nodejs - evented I/O for V8 javascript - runtime executable Changes: nodejs (20.19.2+dfsg-1+deb13u2) trixie-security; urgency=medium . * Upstream security patches: + CVE-2026-21713: use timing-safe comparison in Web Cryptography HMAC + CVE-2026-21717: fix array index hash collision + CVE-2026-21710: http: use null prototype for headersDistinct/trailersDistinct + CVE-2026-21716: include permission check on lib/fs/promises + CVE-2026-21715: add permission check to realpath.native + CVE-2026-21714: handle NGHTTP2_ERR_FLOW_CONTROL error code + CVE-2026-21637: tls wrap SNICallback invocation in try/catch * copyright: add rapidhash from sec/51 patch Checksums-Sha1: 14651770d1d519e8c1ca2da5525b9d320ee59e18 536764 libnode-dev_20.19.2+dfsg-1+deb13u2_riscv64.deb d51bc4b0e44a1c15311ea1762910fd8243508202 951426052 libnode115-dbgsym_20.19.2+dfsg-1+deb13u2_riscv64.deb 8359b9e7904a0c6a31e614f1cf4b1b4b8723aef2 12469316 libnode115_20.19.2+dfsg-1+deb13u2_riscv64.deb 55516b83a7f04d36fa63962991779ec2b522101c 82888 nodejs-dbgsym_20.19.2+dfsg-1+deb13u2_riscv64.deb e4430d609fb943fd8b46a1377dc5b76556f63507 10890 nodejs_20.19.2+dfsg-1+deb13u2_riscv64-buildd.buildinfo 7187ee8ee35edeccff7c029404ae3f7641aa8bad 353356 nodejs_20.19.2+dfsg-1+deb13u2_riscv64.deb Checksums-Sha256: f8f075399b3c95674a969dd77be8f23b8c9c34b3e78cf5a09b844b2a64722bff 536764 libnode-dev_20.19.2+dfsg-1+deb13u2_riscv64.deb 75f8b497021e827d3d337e201203260999c5688ce88aab7752d374305b7b77df 951426052 libnode115-dbgsym_20.19.2+dfsg-1+deb13u2_riscv64.deb 6b4ed40d9cc493d7e3e848b861a850b80d9c1a0aa107ed8ab62d2d9be3a8173e 12469316 libnode115_20.19.2+dfsg-1+deb13u2_riscv64.deb 6b9a4f773264b3dafb2fe470f7e86e4838ce6dcb2ea3c221971ede8c224bb4a2 82888 nodejs-dbgsym_20.19.2+dfsg-1+deb13u2_riscv64.deb 6bffe2bbe4dc6c02077ee26667e917c1d278a8e0063a97dcf0943bab119ef338 10890 nodejs_20.19.2+dfsg-1+deb13u2_riscv64-buildd.buildinfo 4b2711c7b442d56fe292375ba372fe42a8a29969aa1b630b0b4e916f04713f68 353356 nodejs_20.19.2+dfsg-1+deb13u2_riscv64.deb Files: d30d452bcf47506920eaf8eaaa9a9d6c 536764 libdevel optional libnode-dev_20.19.2+dfsg-1+deb13u2_riscv64.deb 4e9b736e7fcc9d19bc1acb3280bcb1ff 951426052 debug optional libnode115-dbgsym_20.19.2+dfsg-1+deb13u2_riscv64.deb c21d66b0722730ac07a4679898c98c7c 12469316 libs optional libnode115_20.19.2+dfsg-1+deb13u2_riscv64.deb f99378a79caf5fe007a5766b7426d8c8 82888 debug optional nodejs-dbgsym_20.19.2+dfsg-1+deb13u2_riscv64.deb dbe7ddeb5127fdb0af34e32ada664934 10890 javascript optional nodejs_20.19.2+dfsg-1+deb13u2_riscv64-buildd.buildinfo 6ba6b8c760a52edf902a902e81f7a387 353356 javascript optional nodejs_20.19.2+dfsg-1+deb13u2_riscv64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE/AxPdLOtOshqz3vw/Fc5EAGpa+sFAmnF7QEACgkQ/Fc5EAGp a+sOoQ/9FwePwDz2oXltOGMrJ2ttzgUB/9tqXedTqb4SF+29cxwQkCHwN+Bf1FAc kJrnkgttucPr555xVPXDybwXMizpH8f8rbRpIluFDwKeKckh4gfHfrMCYtS/Fl4X Vf/lgrJoGUcXL+OxZ9LlSHBfEfUWHVvZKXIRIRAb/BUxrKqjRiQfWelGZXJVh3ro xNlrCV3UGYbze+kCSCvIJNC9qF+TGJ6inhGmYnwsh3sZUHiODpNqXPY25Jj2+aIx c2vwIYgb7+9VWdl5d7/nc30UDTDq3/Ei3Tn48K1QrxcdkWSZoYHX/vwT2eLXgtvd XtNuh7fQIMNRbhREnIwB+4xSuvqkdYB6SIoNeQS0kHx88cENSc1Bp16GUdPKsK1M mu/HfkYb3fM/Tzbla7gn5ypJ8za62MCAGoEhWE64eixIN6uZcTtxQKFyzthdtJ9d 9yJeHzTz38C6V0QpYV8xL+SscJZ5TpUd7dpaVqKOG4mTJuI4bZVRCe34PQzta/ey WC61CKh5CmE1rwH9nb/qL42b+ZpEQo9fofhK/dLg3Lo0tf9Ih35Gh5qFLwf1bAaW wub8YZecKLn+HWMsP1YAESlzYn3kue7PCnK5+sQAmDwycduwsPcXlkIC0sqX7cHg TUdgHRFK/tHrrBb5CMme3TuNfd/LBYRAWdxvKzIcoN0E9RQ2pOE= =MiIG -----END PGP SIGNATURE-----