Your message dated Sat, 03 Oct 2026 07:05:10 +0000
with message-id <[email protected]>
and subject line Bug#1149792: fixed in node-pbkdf2 3.1.7+~3.1.2-1
has caused the Debian Bug report #1149792,
regarding node-pbkdf2: CVE-2026-102414
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1149792: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1149792
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: node-pbkdf2
Version: 3.1.6+~3.1.2-1
X-Debbugs-CC: [email protected]
Severity: important
Tags: security upstream
Forwarded: https://github.com/browserify/pbkdf2/issues/82

Hi,

The following vulnerability was published for node-pbkdf2.

CVE-2026-102414[0]:
| pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's
| block size on every iteration in its JavaScript fallback
| (lib/sync.js). A password longer than the block size (64 bytes, or
| 128 bytes for sha384 and sha512) is passed to HMAC as the key on
| every iteration, and HMAC hashes such keys in full each time. Cost
| is therefore O(iterations × password length), and a long password
| can block the event loop. The fallback is used by pbkdf2Sync and
| pbkdf2 on Node.js before 0.12, on Bun (1.0.0 through 1.1.34, and
| 1.2.6 and later), and on Deno 2.9.0 and later, because their native
| pbkdf2Sync fails the library's feature check. It is also used when
| lib/sync.js is imported directly. Node.js 0.12 and later, and
| browser builds (which use lib/sync-browser.js), are not affected.
| Applications that enforce a reasonable maximum password length are
| not meaningfully affected.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-102414
    https://www.cve.org/CVERecord?id=CVE-2026-102414
[1] https://github.com/browserify/pbkdf2/security/advisories/GHSA-477h-4r7f-fvrx
[2] https://github.com/browserify/pbkdf2/issues/82
[3] 
https://github.com/browserify/pbkdf2/commit/493d8d8ff437f680338bf7397398fda884ad462e

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: node-pbkdf2
Source-Version: 3.1.7+~3.1.2-1
Done: Xavier Guimard <[email protected]>

We believe that the bug you reported is fixed in the latest version of
node-pbkdf2, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Xavier Guimard <[email protected]> (supplier of updated node-pbkdf2 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 03 Oct 2026 08:36:44 +0200
Source: node-pbkdf2
Architecture: source
Version: 3.1.7+~3.1.2-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers 
<[email protected]>
Changed-By: Xavier Guimard <[email protected]>
Closes: 1149792
Changes:
 node-pbkdf2 (3.1.7+~3.1.2-1) unstable; urgency=medium
 .
   * Team upload
   * New upstream release (Closes: #1149792, CVE-2026-102414)
Checksums-Sha1: 
 0a9fc3c3107932206d239b5e75d7e780fc09f5fd 2528 node-pbkdf2_3.1.7+~3.1.2-1.dsc
 2dc43808e9985a2c69ff02e2d2027bd4fe33e8dc 1777 
node-pbkdf2_3.1.7+~3.1.2.orig-types-pbkdf2.tar.gz
 3b15328ae14a1cf3420d2bd4a9c48b274a452658 27060 
node-pbkdf2_3.1.7+~3.1.2.orig.tar.gz
 df4f851c9f4a6c068123fa827da996b48e48f67f 5224 
node-pbkdf2_3.1.7+~3.1.2-1.debian.tar.xz
Checksums-Sha256: 
 a63bb4b990c81a56f34bcea808f0d63078c5136728957049827e613df6fa9a1f 2528 
node-pbkdf2_3.1.7+~3.1.2-1.dsc
 8f5b884c96b470207fb88b99e54a806886df090e55ea33f832f7dd22c203e041 1777 
node-pbkdf2_3.1.7+~3.1.2.orig-types-pbkdf2.tar.gz
 5c703ac1df95e210f551dbb80545457de13d08570ffcb6a196e7eae5897b1107 27060 
node-pbkdf2_3.1.7+~3.1.2.orig.tar.gz
 34be2d23f04f379289eeb8cd36db771dbaefd4b168b94ae862c3785802ae709e 5224 
node-pbkdf2_3.1.7+~3.1.2-1.debian.tar.xz
Files: 
 22f5f164703f49f71c875208295483fc 2528 javascript optional 
node-pbkdf2_3.1.7+~3.1.2-1.dsc
 c7af94f3166ae211d097fc42e6ee1321 1777 javascript optional 
node-pbkdf2_3.1.7+~3.1.2.orig-types-pbkdf2.tar.gz
 1c4426099db485b33f8c08fdbbd060fb 27060 javascript optional 
node-pbkdf2_3.1.7+~3.1.2.orig.tar.gz
 ff794b71362fed844fad8bb9d7f1f460 5224 javascript optional 
node-pbkdf2_3.1.7+~3.1.2-1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmrAovMACgkQ9tdMp8mZ
7un50Q/9EkRyHHm9CpF8r0lJ4YiEj2fjQB3I5VY9fxTS7awJxHnCMFFgClGgrPDz
ScWFSmd9nPwC7CgzfVU+3uHlv985SAxZkJ23KHkM5UVxlW3IDJxusk3Lr4sQV7s/
qxrdqkWFw6R8svKAiYLry0JDhYlww/XSYQB88XZM8lli3vN4m7EEQYwsMEiu/oQQ
8VLBfllQhFZ8awfQsOjcDvNAkjHn8vYDMD+yuiELk002vZX3cQwtLS7y070HTrRO
8+a9d7o7bC15KBTy1ext1k1eRxpnAap+VwNiq5giCx8fl7jcMrSIOMh1eeXIKtGm
ppnGp7h89wgoDuc4l2MXAFnq51c02qJUkOyVv2yfiaClYqaILNVzco1vKjwJCMlt
k3JFirlnfhvlYsIyr0KKjX4CjxCMeIzBAMvaZrqbOLvvMiOD7D6AuTXB8Py5OIwN
x95VV5xdUemP3xClpmDBjup8L6wypkhYb/uvl7wRM0uco8sKQvqiOQ9juDMiFDjm
BPzG1yJAG3iGidFojHG8ELGXlExbrWcMEcZ46szOh9mFMAiBa7wO2ha0dLEZmTkT
QQGcb3gkbITMHmp3OUOUTtK5V++CgcVeazihrfyAMcbKRQlT+oIIN1Fbg5Ov/T3p
tvNDlCfqR6R/s9pvjIHu9+/s5AI+OC/PkxHXYHk8vcvTIfpSams=
=bQ7V
-----END PGP SIGNATURE-----

Attachment: pgprXtEvSgGzu.pgp
Description: PGP signature


--- End Message ---
-- 
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel

Reply via email to