Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:61376 https://access.redhat.com/errata/RHSA-2026:61376
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:61377 https://access.redhat.com/errata/RHSA-2026:61377
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:61386 https://access.redhat.com/errata/RHSA-2026:61386
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:61383 https://access.redhat.com/errata/RHSA-2026:61383
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:62219 https://access.redhat.com/errata/RHSA-2026:62219
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:62416 https://access.redhat.com/errata/RHSA-2026:62416
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:62583 https://access.redhat.com/errata/RHSA-2026:62583
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:64817 https://access.redhat.com/errata/RHSA-2026:64817