Your message dated Tue, 18 Aug 2026 10:04:27 +0000
with message-id <[email protected]>
and subject line Bug#1141821: fixed in node-immutable 4.3.9-1
has caused the Debian Bug report #1141821,
regarding node-immutable: CVE-2026-59879 CVE-2026-59880
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1141821: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141821
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: node-immutable
Version: 4.3.8-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerabilities were published for node-immutable.
CVE-2026-59879[0]:
| Immutable.js provides many Persistent Immutable data structures.
| Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn,
| List#updateIn, and the functional set, setIn, and updateIn mishandle
| an index or size in the range 2 ** 30 to 2 ** 31 in setListBounds in
| src/List.js, causing an empty List to enter an uncatchable infinite
| loop, a populated List to allocate without bound until process
| abort, or setSize to silently wrap large values. This issue is fixed
| in versions 4.3.9 and 5.1.8.
CVE-2026-59880[1]:
| Immutable.js provides many Persistent Immutable data structures.
| Prior to 4.3.9 and 5.1.8, Immutable.Map and Immutable.Set keep keys
| that share the same 32-bit hash in a HashCollisionNode collision
| bucket that is scanned linearly, allowing an attacker who controls
| keys inserted into a Map, such as through Immutable.Map(obj),
| Immutable.fromJS(obj), state.merge(userObject), or mergeDeep, to
| craft many colliding keys and degrade insertion and lookup to
| consume disproportionate CPU. This issue is fixed in versions 4.3.9
| and 5.1.8.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-59879
https://www.cve.org/CVERecord?id=CVE-2026-59879
[1] https://security-tracker.debian.org/tracker/CVE-2026-59880
https://www.cve.org/CVERecord?id=CVE-2026-59880
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: node-immutable
Source-Version: 4.3.9-1
Done: Xavier Guimard <[email protected]>
We believe that the bug you reported is fixed in the latest version of
node-immutable, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Xavier Guimard <[email protected]> (supplier of updated node-immutable package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Tue, 18 Aug 2026 11:37:49 +0200
Source: node-immutable
Architecture: source
Version: 4.3.9-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers
<[email protected]>
Changed-By: Xavier Guimard <[email protected]>
Closes: 1141821
Changes:
node-immutable (4.3.9-1) unstable; urgency=medium
.
* Team upload
* Declare compliance with policy 4.7.4
* Drop "Priority: optional"
* New upstream version (Closes: #1141821, CVE-2026-59879, CVE-2026-59880)
Checksums-Sha1:
94aa948b73c8615ec8b6c8d31113cdbe3b7f585d 2265 node-immutable_4.3.9-1.dsc
493e81d01ea81921d48395b59fe9184381058f31 994343
node-immutable_4.3.9.orig.tar.gz
b901095aa3043ea7e740ddfee6de6b1d3f241154 73720
node-immutable_4.3.9-1.debian.tar.xz
Checksums-Sha256:
3d226cdba3fe83a8df537ab3f77b27caba161cd2e89679056aeceb208a901d90 2265
node-immutable_4.3.9-1.dsc
d4738b9a41a412907ca8e4ac819fcbe985750cfcb1e1c438197cd756e373b649 994343
node-immutable_4.3.9.orig.tar.gz
4803aad87b6f54be5fe6cd99e8be21d8ea3b10c4c06fcf7f70608f31bed7461f 73720
node-immutable_4.3.9-1.debian.tar.xz
Files:
12cb52586568e740b5a9536940c2149a 2265 javascript optional
node-immutable_4.3.9-1.dsc
a20b18fe6e3a4105d8f6ae1aa9c88b55 994343 javascript optional
node-immutable_4.3.9.orig.tar.gz
a5637e826a1803312fbb3313e3d58a73 73720 javascript optional
node-immutable_4.3.9-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmqEKLsACgkQ9tdMp8mZ
7um3XA//Z+6dKwa9MO+Pj6TA5jgnDQIRXSSMvzzFVKPnr9bewUoYUuAoMemr7g0V
ulNiBxc2k3S/aAcYG/B7kZdbrCHyrLdcEaIFETxp6fWzG56VQ73hfJO+t08DaS9d
piManGWLdPpYjtHEqZahGSiBO/zcktzZeM7rdoDxpuEVeROtLpoLbsNKqDJbZSDm
MMneol5X6ud0nDUoz+U7QXURv6OwCXUeVgx7I+WRs9vN6Uwg2Aag4JWYLAz9lvOn
j/VaTVfLwNsH2y7kUhMM3NGPs7My5Sb6E37Cj1+6EElWlnpzrXnyH/+Ft71Fv7fQ
ysABseoacK/jORjNh59f54iHBnxK9E4xhheIfIwWUGyBUMKCmWNLeoa49ICIim7U
1Mnf86ej5J7TX0PO16u9jlIN/KDKH3CAhHP2zWbZuI67KSuQ0UFzOoHbF6FGSWzk
4KugPdQyQoXAuZLMXFMSXnfP8rXJ1X1OBNdRU+gcWRRZzEqqiT4shv3pqjSUjuur
qFp8gI65bzbR6Dfsq8P0JlfOnpTV5Bu3ti+dlmcaV+2PU3MhwmouXmd5HhznFu43
Wv2bd+ovWJgUWLeKz7e2kJEQYrfY7PmD/OeiGRU++TZD6F9cHAiDh81s8401oqdo
rBdIZnx4MqIqP/tIQjp9miK8K249zh6EX6KP2JOWsWJm5PjJW2o=
=HJtH
-----END PGP SIGNATURE-----
pgphTbhoqhZta.pgp
Description: PGP signature
--- End Message ---
--
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel