Your message dated Sat, 08 Aug 2026 09:04:29 +0000
with message-id <[email protected]>
and subject line Bug#1143179: fixed in node-re2 1.26.1+~cs1.7.0-1
has caused the Debian Bug report #1143179,
regarding node-re2: CVE-2026-68499 CVE-2026-67550
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1143179: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143179
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: node-re2
Version: 1.25.0+~cs1.6.0-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerabilities were published for node-re2.
CVE-2026-68499[0]:
| re2 provides Node.js bindings for Google's RE2 regular expression
| engine. Prior to 1.25.2, re2's String.prototype.match implementation
| with a global RE2 pattern that can match the empty string fails to
| advance its native matching cursor in lib/match.cc, causing an
| infinite loop and unbounded native memory growth that blocks the
| event loop and can exhaust host memory. This issue is fixed in
| 1.25.2.
CVE-2026-67550[1]:
| re2 provides Node.js bindings for Google's RE2 regular expression
| engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8
| byte length of a subject but uses it as a UTF-16 code-unit offset in
| exec, test, match, replace, and split, allowing an attacker-
| influenced lastIndex on a non-ASCII subject to trigger an out-of-
| bounds heap read and an uncatchable process crash, with limited heap
| information disclosure in some cases. This issue is fixed in 1.25.2.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-68499
https://www.cve.org/CVERecord?id=CVE-2026-68499
https://github.com/uhop/node-re2/security/advisories/GHSA-6hxr-mr5r-9836
[1] https://security-tracker.debian.org/tracker/CVE-2026-67550
https://www.cve.org/CVERecord?id=CVE-2026-67550
https://github.com/uhop/node-re2/security/advisories/GHSA-ff84-5f28-78qj
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: node-re2
Source-Version: 1.26.1+~cs1.7.0-1
Done: Xavier Guimard <[email protected]>
We believe that the bug you reported is fixed in the latest version of
node-re2, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Xavier Guimard <[email protected]> (supplier of updated node-re2 package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 08 Aug 2026 10:50:32 +0200
Source: node-re2
Architecture: source
Version: 1.26.1+~cs1.7.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers
<[email protected]>
Changed-By: Xavier Guimard <[email protected]>
Closes: 1143179 1143901
Changes:
node-re2 (1.26.1+~cs1.7.0-1) unstable; urgency=medium
.
* Team upload
* New upstream version 1.26.1+~cs1.7.0 (Closes: #1143179, #1143901,
CVE-2026-67550, CVE-2026-68499, CVE-2026-71430, CVE-2026-71498)
Checksums-Sha1:
9947e92d83416c830e4edf7c18bbefb564b5d48e 2472 node-re2_1.26.1+~cs1.7.0-1.dsc
83a530097109a1454208d6059a1d4266870bc111 55221
node-re2_1.26.1+~cs1.7.0.orig-install-artifact-from-github.tar.gz
6f1027fc6241ab91fdfe0785aec19795efa54da1 150630
node-re2_1.26.1+~cs1.7.0.orig.tar.gz
8046137c299f913d4e8cbb5b92bdca379ac416ad 17812
node-re2_1.26.1+~cs1.7.0-1.debian.tar.xz
Checksums-Sha256:
6ce1224193a279eaa25b43edf02d9ba8225487f1f2109f5fe6dfb3f07aaa61f4 2472
node-re2_1.26.1+~cs1.7.0-1.dsc
54d5c58a9dfc240f27f54d9a146348f452159a052afbcb5ee82de80b004fe55b 55221
node-re2_1.26.1+~cs1.7.0.orig-install-artifact-from-github.tar.gz
44462045d5fb13b204e49b51fd8960df66d81dbcf16644fc7b7f1208c805dced 150630
node-re2_1.26.1+~cs1.7.0.orig.tar.gz
9bafddd55c919b6dae17a95e18df83e9c12632d1c68591052206ee0024e9058f 17812
node-re2_1.26.1+~cs1.7.0-1.debian.tar.xz
Files:
b8eeadaee5bc12b33c3cffe05654d070 2472 javascript optional
node-re2_1.26.1+~cs1.7.0-1.dsc
93d9d098b3d5ea6c4231ec5da9abc2a8 55221 javascript optional
node-re2_1.26.1+~cs1.7.0.orig-install-artifact-from-github.tar.gz
db3cb5fe112249d5e836347493c6605d 150630 javascript optional
node-re2_1.26.1+~cs1.7.0.orig.tar.gz
b317c406c0aa1434b314714958caec15 17812 javascript optional
node-re2_1.26.1+~cs1.7.0-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmp27nUACgkQ9tdMp8mZ
7ukZ9g//RIek0RMD74/DGqT5IVTL9mm8Uzx95vecJdGxCMEgU/Wnaeu+lzEpn+jf
WBcIFmfPhbiUndxmthJDBF3Pr5kB0nNyKbPGL034IEDk7ZrKsS+CZ2mpDmboIEMO
olpSGa9Hr/GekPza2ZQ0ljgKVEt4Mn5BRzHMZbYRZDrBPSdW30SXEXcgvfiaw6Fn
6+K2fO9swuNf5d6dq1e9ZO5kDLaWnCJltBGfRSmXzfcqqEaHw1WZW1G3DV+lTSjx
PrOk0xnBeyWWp4uyPUzQmehRXXu8ArVy5M6cO1Nq+6BD9yN/sboBxizYpd4u2pNl
zSXfzW5RJkO2K1dH/WV9gPL7RxegAjmUOmInasRPmwmP61riXFRoEAtvyYhTls4G
ci2VwZk5wyIsr3G7YDqIJL/OyDbfMBxNNBTCpP0XkeZapENDsRusyBjxQ8W6VjEf
/8FCDw0Tv/z2hsNzK1tQlZpwsHs6yHY8X2y0+TG2UmTux8CCCPXEWF6ExrPder0g
lJdGwgGnS+KXU7RF5xNhfbD3FKBnyCcSdXYuGnSBaQiDV8IffMtaS/3hS5jjwaMi
fL8G0twoCeJ18OSSmR3cEUcpuvQbFC2bvk3A2JNoU5YglNTFltn/5qI8hufXCghE
tnBL0GYtDcCTked4Mr8DUNIo/J9+Jt3Nvtfqfseucn0KrTkd/GY=
=JwrI
-----END PGP SIGNATURE-----
pgpsEtz9TaNin.pgp
Description: PGP signature
--- End Message ---
--
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel