nodejs24/sources
tjuhasz cafce37fa3 Update to version 24.19.0
CVE fixes included in rebase:
CVE-2026-56846 - http2: retained headers can bypass maxSessionMemory limits,
 allowing remote memory exhaustion
CVE-2026-56848 - http2: re-entrant send during nghttp2_session_mem_recv() can
 cause heap-use-after-free
CVE-2026-58043 - permission: path matching can over-grant filesystem access
 across radix-tree prefix boundaries
 Blog: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases

Also following CVEs with lower severity:
CVE-2026-56850, CVE-2026-58040, CVE-2026-58041, CVE-2026-58042,
CVE-2026-58045, CVE-2026-56847, CVE-2026-58039, CVE-2026-58044

Regenerate tar CVE patch (0001-CVE-2026-59873-CVE-2026-59874) against
24.19.0 base, which ships tar 7.5.16 instead of 7.5.15.

Disable LTO (--enable-lto) to fix segfault at startup caused by
miscompilation with the new snapshot-in-libnode build changes in 24.19.0.

Remove wasm-allocation test from test list: the test requires RLIMIT_AS
set to 20GB to trigger OOM on WebAssembly.Memory allocations, which the
RPM build environment does not enforce.

Resolves: RHEL-234904 RHEL-234828 RHEL-234382
2026-08-31 16:40:42 +02:00

5 lines
667 B
Plaintext

SHA512 (node-v24.19.0-stripped.tar.gz) = 9bf298927f789151276a0ba4325735ba1b0a8e8ce481abef3a04b049acd11ea542078ce40f1cda5bc628bed0ebb9adddba1e8600a9f686b649e9dacad321cbf7
SHA512 (icu4c-78.3-data-bin-b.zip) = 99e984f706423eccd14507c43d479a116a69ccbcf28af765d4dad7d6397eaa9be60208febf45efefc1932479c7b26d3246d2c08b20f99ad9b81512761726b5a4
SHA512 (icu4c-78.3-data-bin-l.zip) = 4f0f083fe62c35da76a150498e04230bc2dfba6c07f32781f5173c13c3e1237e4157fa312dabb69909f495b84334f1ef544244268efa667927b20350a1d3d455
SHA512 (packaging-scripts.tar.gz) = 09e566ddf0b9d613ec0714fc191f214473b36f636ebf08eaf333429bc4abac8dc9356fcc9292cf67e5900e327b1a21223ef552b27f0d01f92cf9fd8ed6edff36