Release date:
2026-09-08 12:28:18 UTC
Description:
- CVE-2026-56846: http2: retain header memory in session accounting, so a
header block handed to JS by Http2Session::HandleHeadersFrame() stays
charged against maxSessionMemory until the stream is removed, instead of
being un-charged while the JS objects can still keep it alive
- CVE-2026-56848: http2: defer rst stream while in scope, so submitting
RST_STREAM with NGHTTP2_REFUSED_STREAM from inside an nghttp2 receive
callback flushes the frame instead of force-purging pending data, which
re-entered nghttp2's send path and freed streams the active receive was
still using
Updated packages:
-
alt-nodejs20-nodejs-20.20.2-11.el8.x86_64.rpm
sha:0cea3d7a035dbf94ed6d58598b792905804200a26bc4588943fe4329f4a81dcc
-
alt-nodejs20-nodejs-devel-20.20.2-11.el8.x86_64.rpm
sha:83b073d7f67c399469be1f639bb3183b44818ee9987b2f44a839091f2f5d7548
-
alt-nodejs20-nodejs-docs-20.20.2-11.el8.noarch.rpm
sha:388172c43e16c6c37ffc91dda4d2f8a8a043d9d0cd8d6c8de997005a59e5fdc5
-
alt-nodejs20-npm-10.8.2-20.20.2.11.el8.x86_64.rpm
sha:e4a54509424c7d6c900882eac4be36049d27c53ac20df84908a6f1fc1de19ff3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.