Release date:
2026-09-08 12:32:59 UTC
Description:
- CVE-2026-56846: http2: retain header memory in session accounting, so a
header block handed to JS by Http2Session::HandleHeadersFrame() stays
charged against maxSessionMemory until the stream is removed, instead of
being un-charged while the JS objects can still keep it alive
- CVE-2026-56848: http2: defer rst stream while in scope, so submitting
RST_STREAM with NGHTTP2_REFUSED_STREAM from inside an nghttp2 receive
callback flushes the frame instead of force-purging pending data, which
re-entered nghttp2's send path and freed streams the active receive was
still using
Updated packages:
-
alt-nodejs20-nodejs-20.20.2-11.el10.x86_64.rpm
sha:ab0bc9c539045a460f03e82003ef42476556558004b8a39815769c572bda8641
-
alt-nodejs20-nodejs-devel-20.20.2-11.el10.x86_64.rpm
sha:416d47b14664d40d815f750bcb2b27ab17d152af0bc1f905109222a9972f632b
-
alt-nodejs20-nodejs-docs-20.20.2-11.el10.noarch.rpm
sha:dbe9ba77dba6d2f7304aca5c3ceb84dfa2c1b84efcc2322b8c657fe6f63e3a11
-
alt-nodejs20-npm-10.8.2-20.20.2.11.el10.x86_64.rpm
sha:003ac3d668fed5a2e6201fd53a4bf1613a887e71bd43e7afe50a64192702314b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.