[ubuntu/jammy-security] node-sha.js 2.4.11+~2.4.0-1ubuntu0.1 (Accepted)

John Breton john.breton at canonical.com
Thu Sep 25 13:22:02 UTC 2025


node-sha.js (2.4.11+~2.4.0-1ubuntu0.1) jammy-security; urgency=medium

  * SECURITY UPDATE: improper input validation
    - debian/patches/CVE-2025-9288-1.patch: Validate input types in hash.js.
    - debian/patches/CVE-2025-9288-2.patch: Embed to-buffer.js and its
      dependencies in node_modules.
    - debian/control: Add node-get-intrinsic, node-isarray, and
      node-is-typed-array to Depends.
    - debian/copyright: Add copyright details for embedded Node modules.
    - debian/install: Install embedded Node modules.
    - CVE-2025-9288

Date: 2025-09-24 17:25:13.858415+00:00
Changed-By: Edwin Jiang <edwin.jiang at canonical.com>
Signed-By: John Breton <john.breton at canonical.com>
https://launchpad.net/ubuntu/+source/node-sha.js/2.4.11+~2.4.0-1ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list