[CLSA-2026:1786981618] Fix CVE(s): CVE-2026-48937
Type:
security
Severity:
Low
Release date:
2026-08-17 15:47:08 UTC
Description:
* SECURITY UPDATE: HTTP/2 session left alive after an internal GOAWAY - debian/patches/CVE-2026-48937.patch: when nghttp2 hits a low-level protocol error it calls nghttp2_session_terminate_session() itself, which queues a GOAWAY and returns success from nghttp2_session_mem_recv() without invoking any application-level callback. Node therefore never learned the session had died: no 'error', no 'close', and the Http2Session kept its streams, buffers and handle alive on a dead socket, which an unauthenticated peer could repeat to exhaust memory and handles. Http2Session::OnFrameSent() now flags a GOAWAY that we did not initiate ourselves and SendPendingData() raises NGHTTP2_ERR_PROTO to JavaScript once the GOAWAY has been written (backport of nodejs/node@a8a0d128; the !IsGracefulCloseInitiated() term is dropped because Node 14 has no graceful_close_initiated_ flag -- session.close() reaches the native layer through Http2Session::Goaway(), covered by the new goaway_initiated_ flag, and Http2Session::Close() sets the closing flag before terminating the session). Only the new regression test is taken from upstream: the flow-control test changes there track nghttp2 v1.67.0+ behaviour, while this release bundles 1.42.0, where a stream-level flow control violation still yields RST_STREAM - CVE-2026-48937
CVEs fixed:
Updated packages:
  • alt-nodejs14-docs_14.21.3-27_amd64.deb
    sha:de4736bc246edab556c8a125f4670b9af1b34a2e
  • alt-nodejs14-nodejs_14.21.3-27_amd64.deb
    sha:d8ce5f42e2839535a01a6bd53ae2e099cdb14196
  • alt-nodejs14-nodejs-devel_14.21.3-27_amd64.deb
    sha:f53a2c228915e62a496375feb2e4705eaeb562b0
  • alt-nodejs14-npm_6.14.18-14.21.3-27_amd64.deb
    sha:bb20c0e53df604ee57cb1c9cf3a59b376b2154ee
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.