]> dgit.raspbian.org Git - nodejs.git/commitdiff
Merge version 18.20.4+dfsg-1~deb12u2+rpi1 and 18.20.4+dfsg-1~deb12u3 to produce 18... bookworm-staging archive/raspbian/18.20.4+dfsg-1_deb12u3+rpi1 raspbian/18.20.4+dfsg-1_deb12u3+rpi1
authorRaspbian automatic forward porter <root@raspbian.org>
Thu, 1 Oct 2026 23:20:36 +0000 (00:20 +0100)
committerRaspbian automatic forward porter <root@raspbian.org>
Thu, 1 Oct 2026 23:20:36 +0000 (00:20 +0100)
1  2 
debian/changelog

index 37ff3975848699e27e09e3c1bf6a47d1e91476f3,cd378b1c1bae9799425f8904f12d6fcb5eeefd0c..f256a8b33ee58b4ae849d5f95def4128a065b261
@@@ -1,11 -1,62 +1,71 @@@
- nodejs (18.20.4+dfsg-1~deb12u2+rpi1) bookworm-staging; urgency=medium
++nodejs (18.20.4+dfsg-1~deb12u3+rpi1) bookworm-staging; urgency=medium
 +
 +  [changes brought forward from 18.10.0+dfsg-6+rpi1 by Peter Michael Green <plugwash@raspbian.org> at Tue, 15 Nov 2022 03:51:54 +0000]
 +  * Set --with-arm-version=6 on raspbian.
 +  * Use armv6k CFLAGS on raspbian.
 +  * Disable testsuite.
 +
-  -- Raspbian forward porter <root@raspbian.org>  Tue, 19 May 2026 00:07:39 +0000
++ -- Raspbian forward porter <root@raspbian.org>  Thu, 01 Oct 2026 23:20:35 +0000
++
+ nodejs (18.20.4+dfsg-1~deb12u3) bookworm-security; urgency=high
+ 
+   * Team upload
+   * Fix CVE-2026-48618:
+     A flaw in Node.js TLS hostname handling can cause Node.js
+     unicode dot separator handling can lead to tls wildcard-depth
+     authentication bypass due to resolver and verifier hostname
+     normalization mismatch
+   * Fix CVE-2026-48618:
+     A flaw in Node.js TLS hostname handling can cause Node.js unicode
+     dot separator handling can lead to tls wildcard-depth
+     authentication bypass due to resolver and verifier hostname
+     normalization mismat. This can lead to confidentiality impact
+     or bypass of the intended security boundary under
+     affected configurations.
+   * Fix CVE-2026-48928: case-sensitive SNI context matching
+     The regex constructed by server.addContext() lacked the case-insensitive
+     flag, causing uppercase or mixed-case SNI hostnames from ClientHello to
+     miss their intended context and fall back to the default context. This
+     violates RFC 6066 Section 3, which states that DNS hostnames are
+     case-insensitive. In mTLS configurations with per-tenant contexts, this
+     allowed bypassing client certificate authorization by simply
+     uppercasing the SNI hostname.
+   * Fix CVE-2026-48930:
+     A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames
+     can lead to silent authority rebinding due to c-string truncation
+     in resolver bindings.
+   * Fix CVE-2026-48931:
+     HTTP Agent can cause a client to accept as valid a response
+     that is send before the client has sent the request.
+   * Fix CVE-2026-48933:
+     A flaw in Node.js WebCrypto implementation can crash the process
+     if the input of `subtle.encrypt()` is a multiple of 2GiB.
+   * Fix CVE-2026-48934:
+     A flaw in Node.js TLS host verification can cause an attacker
+     to bypass certification validation.
+   * Fix CVE-2026-56846
+     A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained
+     header blocks evade maxSessionMemory
+     and enable remote memory exhaustion.
+   * Fix CVE-2026-56848:
+     A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()`
+     to be called re-entrantly while `nghttp2_session_mem_recv()` is executing,
+     resulting in a heap-use-after-free.
+   * Fix CVE-2026-56850:
+     A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array
+     key collisions, allowing mutual TLS (mTLS) client identities to be
+     reused across requests configured with different client certificates.
+   * Fix CVE-2026-58042:
+     A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process
+     When a DNS Response Contains More Than 256 A Records.
+     Repeated triggering of this condition can lead to denial of service.
+   * Fix CVE-2026-58040:
+     An incomplete fix has been identified in Node.js:
+     HTTPS Agent TLS session reuse skips hostname verification across
+     identity policies (incomplete fix of CVE-2026-48934).
+   * Fix FTBFS due to openssl changes
+ 
+  -- Bastien Roucariès <rouca@debian.org>  Sun, 16 Aug 2026 19:34:06 +0200
  
  nodejs (18.20.4+dfsg-1~deb12u2) bookworm-security; urgency=medium