CVE fixes included in rebase: CVE-2026-56846 - http2: retained headers can bypass maxSessionMemory limits, allowing remote memory exhaustion CVE-2026-56848 - http2: re-entrant send during nghttp2_session_mem_recv() can cause heap-use-after-free CVE-2026-58043 - permission: path matching can over-grant filesystem access across radix-tree prefix boundaries Blog: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases Also following CVEs with lower severity: CVE-2026-56850, CVE-2026-58040, CVE-2026-58041, CVE-2026-58042, CVE-2026-58045, CVE-2026-56847, CVE-2026-58039, CVE-2026-58044 Regenerate tar CVE patch (0001-CVE-2026-59873-CVE-2026-59874) against 24.19.0 base, which ships tar 7.5.16 instead of 7.5.15. Disable LTO (--enable-lto) to fix segfault at startup caused by miscompilation with the new snapshot-in-libnode build changes in 24.19.0. Remove wasm-allocation test from test list: the test requires RLIMIT_AS set to 20GB to trigger OOM on WebAssembly.Memory allocations, which the RPM build environment does not enforce. Resolves: RHEL-234904 RHEL-234828 RHEL-234382
5 lines
667 B
Plaintext
5 lines
667 B
Plaintext
SHA512 (node-v24.19.0-stripped.tar.gz) = 9bf298927f789151276a0ba4325735ba1b0a8e8ce481abef3a04b049acd11ea542078ce40f1cda5bc628bed0ebb9adddba1e8600a9f686b649e9dacad321cbf7
|
|
SHA512 (icu4c-78.3-data-bin-b.zip) = 99e984f706423eccd14507c43d479a116a69ccbcf28af765d4dad7d6397eaa9be60208febf45efefc1932479c7b26d3246d2c08b20f99ad9b81512761726b5a4
|
|
SHA512 (icu4c-78.3-data-bin-l.zip) = 4f0f083fe62c35da76a150498e04230bc2dfba6c07f32781f5173c13c3e1237e4157fa312dabb69909f495b84334f1ef544244268efa667927b20350a1d3d455
|
|
SHA512 (packaging-scripts.tar.gz) = 09e566ddf0b9d613ec0714fc191f214473b36f636ebf08eaf333429bc4abac8dc9356fcc9292cf67e5900e327b1a21223ef552b27f0d01f92cf9fd8ed6edff36
|