Release date:
2026-09-08 11:10:59 UTC
Description:
- CVE-2026-56846: http2: retain header memory in session accounting, so a
header block handed to JS by Http2Session::HandleHeadersFrame() stays
charged against maxSessionMemory until the stream is removed, instead of
being un-charged while the JS objects can still keep it alive
- CVE-2026-56848: http2: defer rst stream while in scope, so submitting
RST_STREAM with NGHTTP2_REFUSED_STREAM from inside an nghttp2 receive
callback flushes the frame instead of force-purging pending data, which
re-entered nghttp2's send path and freed streams the active receive was
still using
Updated packages:
-
alt-nodejs20-nodejs-20.20.2-11.el7.x86_64.rpm
sha:d81ed0a5a43fd7ecf425017b833d6c80d7d401f38c7794f6f11e5518f5119898
-
alt-nodejs20-nodejs-devel-20.20.2-11.el7.x86_64.rpm
sha:a69076ab4894386c1cdc6d311ae321a2f1522f1477d8a9dbe009cff6d177fcb2
-
alt-nodejs20-nodejs-docs-20.20.2-11.el7.noarch.rpm
sha:cca1de834593ffa4104aa1af1e3dc741492b1b80e3c3e4fc98a7840ff31c6328
-
alt-nodejs20-npm-10.8.2-20.20.2.11.el7.x86_64.rpm
sha:70d56cbc8c1e0212ce47fce1ffc3087660f721ee087a3408f80ccc9060d255bd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.