[Git][security-tracker-team/security-tracker][master] 2 commits: Add commit for sqlite nodejs

Bastien Roucariès (@rouca) rouca at debian.org
Sun Aug 16 13:28:31 BST 2026



Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker


Commits:
bd6a3538 by Bastien Roucariès at 2026-08-16T14:25:22+02:00
Add commit for sqlite nodejs

- - - - -
e99dbadd by Bastien Roucariès at 2026-08-16T14:27:32+02:00
LTS triagging

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -18866,7 +18866,11 @@ CVE-2026-58042 (A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js
 	NOTE: Fixed by: https://github.com/nodejs/node/commit/22efc051a3c3b3bbddbb3cb06ce1ca5775923c01 (v22.23.2)
 CVE-2026-58041 (A flaw in Node.js node:sqlite allows a stale StatementSyncIterator cre ...)
 	- nodejs 24.19.0+dfsg+~cs24.13.3-1
+	[bookworm] - nodejs <not-affected> (vulnerable code introduced in v22 with experimental sqlite module)
+	[bullseye] - nodejs <not-affected> (vulnerable code introduced in v22 with experimental sqlite module)
 	NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#nodesqlite-sqltagstore-iterator-replay-can-re-execute-writes-cve-2026-58041---medium
+	NOTE: Fixed by commit: https://github.com/nodejs/node/commit/af9ff0490ce834f3b28efbc2551f96a03a829fd2 (v24.18.1)
+	NOTE: experimental status for v22
 CVE-2026-56848 (A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()`  ...)
 	- nodejs 24.19.0+dfsg+~cs24.13.3-1
 	NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#http2-re-entrant-send-can-cause-heap-use-after-free-cve-2026-56848---high



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/376476f2c72d19a9339552385a791468b5201941...e99dbadd9ecc0aa4e9e6b739cef11115d9506e51

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/376476f2c72d19a9339552385a791468b5201941...e99dbadd9ecc0aa4e9e6b739cef11115d9506e51
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260816/1321b043/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list