[Git][security-tracker-team/security-tracker][master] 2 commits: Add commit for sqlite nodejs
Bastien Roucariès (@rouca)
rouca at debian.org
Sun Aug 16 13:28:31 BST 2026
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker
Commits:
bd6a3538 by Bastien Roucariès at 2026-08-16T14:25:22+02:00
Add commit for sqlite nodejs
- - - - -
e99dbadd by Bastien Roucariès at 2026-08-16T14:27:32+02:00
LTS triagging
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -18866,7 +18866,11 @@ CVE-2026-58042 (A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js
NOTE: Fixed by: https://github.com/nodejs/node/commit/22efc051a3c3b3bbddbb3cb06ce1ca5775923c01 (v22.23.2)
CVE-2026-58041 (A flaw in Node.js node:sqlite allows a stale StatementSyncIterator cre ...)
- nodejs 24.19.0+dfsg+~cs24.13.3-1
+ [bookworm] - nodejs <not-affected> (vulnerable code introduced in v22 with experimental sqlite module)
+ [bullseye] - nodejs <not-affected> (vulnerable code introduced in v22 with experimental sqlite module)
NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#nodesqlite-sqltagstore-iterator-replay-can-re-execute-writes-cve-2026-58041---medium
+ NOTE: Fixed by commit: https://github.com/nodejs/node/commit/af9ff0490ce834f3b28efbc2551f96a03a829fd2 (v24.18.1)
+ NOTE: experimental status for v22
CVE-2026-56848 (A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` ...)
- nodejs 24.19.0+dfsg+~cs24.13.3-1
NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#http2-re-entrant-send-can-cause-heap-use-after-free-cve-2026-56848---high
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/376476f2c72d19a9339552385a791468b5201941...e99dbadd9ecc0aa4e9e6b739cef11115d9506e51
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/376476f2c72d19a9339552385a791468b5201941...e99dbadd9ecc0aa4e9e6b739cef11115d9506e51
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260816/1321b043/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list