Release date:
2026-08-17 15:51:32 UTC
Description:
* SECURITY UPDATE: HTTP/2 session left alive after an internal GOAWAY
- debian/patches/CVE-2026-48937.patch: when nghttp2 hits a low-level
protocol error it calls nghttp2_session_terminate_session() itself, which
queues a GOAWAY and returns success from nghttp2_session_mem_recv()
without invoking any application-level callback. Node therefore never
learned the session had died: no 'error', no 'close', and the
Http2Session kept its streams, buffers and handle alive on a dead socket,
which an unauthenticated peer could repeat to exhaust memory and handles.
Http2Session::OnFrameSent() now flags a GOAWAY that we did not initiate
ourselves and SendPendingData() raises NGHTTP2_ERR_PROTO to JavaScript
once the GOAWAY has been written (backport of nodejs/node@a8a0d128;
the !IsGracefulCloseInitiated() term is dropped because Node 14 has no
graceful_close_initiated_ flag -- session.close() reaches the native
layer through Http2Session::Goaway(), covered by the new
goaway_initiated_ flag, and Http2Session::Close() sets the closing flag
before terminating the session). Only the new regression test is taken
from upstream: the flow-control test changes there track nghttp2 v1.67.0+
behaviour, while this release bundles 1.42.0, where a stream-level flow
control violation still yields RST_STREAM
- CVE-2026-48937
Updated packages:
-
alt-nodejs14-docs_14.21.3-27_amd64.deb
sha:1e7d0184b6471dab6edc07bbdb9dcf5ad0dc36c0
-
alt-nodejs14-nodejs_14.21.3-27_amd64.deb
sha:85323c83d9976f2fe5e76931c218781ff472dff4
-
alt-nodejs14-nodejs-devel_14.21.3-27_amd64.deb
sha:89039ac613850f7a70a130b4521b5d66336ccad6
-
alt-nodejs14-npm_6.14.18-14.21.3-27_amd64.deb
sha:788d3c63984d4301b178a1396ba9d21d0d6b0f31
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.