Release date:
2026-06-12 10:05:25 UTC
Description:
* SECURITY UPDATE: HTTP/2 Rapid Reset (CVE-2023-44487) — a peer can cause a
denial of service by rapidly opening and cancelling HTTP/2 streams
(HEADERS immediately followed by RST_STREAM) without bound; the flaw is in
the bundled nghttp2 library (1.47.0)
- debian/patches/CVE-2023-44487.patch: minimal backport of the upstream
nghttp2 RST_STREAM rate-limit mitigation (token bucket, burst=1000
rate=33/s) to deps/nghttp2; once the per-connection budget is exhausted
a GOAWAY is sent. Cherry-pick of nghttp2 commit 72b4af6143 (shipped in
1.57.0), no wholesale version bump (Node 16 went EOL before the upstream
fix, so no fixed 16.x exists)
- CVE-2023-44487
Updated packages:
-
alt-nodejs16-docs_16.20.2-21_amd64.deb
sha:4dfb0aae54c08c9200c7a5380ae003c9143ded42
-
alt-nodejs16-nodejs_16.20.2-21_amd64.deb
sha:08581bf8862d82fc59c83d14b01a35c106474656
-
alt-nodejs16-nodejs-devel_16.20.2-21_amd64.deb
sha:e04bcd9412b2393158df98ca08a53a7cb592dcaa
-
alt-nodejs16-npm_8.19.4-16.20.2-21_amd64.deb
sha:bc1679488ac8c303f1b2f2992546f417fa196ceb
-
alt-nodejs16-docs_16.20.2-21_arm64.deb
sha:b7ee2317981f2c4ad19a6ba668e6dfafafd10dc5
-
alt-nodejs16-nodejs_16.20.2-21_arm64.deb
sha:942b1c57eab94736cdbed49249b1a63308fed9fa
-
alt-nodejs16-nodejs-devel_16.20.2-21_arm64.deb
sha:82fba42aafef772736921c7ac2d065cfd84fc96b
-
alt-nodejs16-npm_8.19.4-16.20.2-21_arm64.deb
sha:1b4e500b4879e576d3177a98264c39e2999aa11d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.