[CLSA-2026:1788865405] alt-nodejs20-nodejs: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-09-08 11:03:36 UTC
Description:
- CVE-2026-56846: http2: retain header memory in session accounting, so a header block handed to JS by Http2Session::HandleHeadersFrame() stays charged against maxSessionMemory until the stream is removed, instead of being un-charged while the JS objects can still keep it alive - CVE-2026-56848: http2: defer rst stream while in scope, so submitting RST_STREAM with NGHTTP2_REFUSED_STREAM from inside an nghttp2 receive callback flushes the frame instead of force-purging pending data, which re-entered nghttp2's send path and freed streams the active receive was still using
Updated packages:
  • alt-nodejs20-nodejs-20.20.2-11.el9.x86_64.rpm
    sha:bc6133c7a38560e491d4cfcf30b6b5cea9aa6f9e011dae3c392bb098b7acbc66
  • alt-nodejs20-nodejs-devel-20.20.2-11.el9.x86_64.rpm
    sha:5b86f7be9908d5e70a8a1e615318acaf9798924da9aa70eefa9d0581a3be8b9d
  • alt-nodejs20-nodejs-docs-20.20.2-11.el9.noarch.rpm
    sha:fe9be14561ff2f7739f2378f5a9b8af22fc13ada7b85d7ab0ae289b51c0b6d89
  • alt-nodejs20-npm-10.8.2-20.20.2.11.el9.x86_64.rpm
    sha:0fecc82ba63e52bf783b8fe787d634553e893113d65d23d45a1c8dd0ec3f0694
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.