Amazon Linux 2023 Security Advisory: ALAS2023-2026-1647
Advisory Released Date: 2026-05-14
Advisory Updated Date: 2026-05-14
nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available. (CVE-2026-27135)
Affected Packages:
nodejs24
Issue Correction:
Run dnf update nodejs24 --releasever 2023.11.20260511 or dnf update --advisory ALAS2023-2026-1647 --releasever 2023.11.20260511 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
aarch64:
nodejs24-libs-debuginfo-24.15.0-1.amzn2023.0.2.aarch64
nodejs24-debuginfo-24.15.0-1.amzn2023.0.2.aarch64
v8-13.6-devel-13.6.233.17-1.24.15.0.1.amzn2023.0.2.aarch64
nodejs24-full-i18n-24.15.0-1.amzn2023.0.2.aarch64
nodejs24-devel-24.15.0-1.amzn2023.0.2.aarch64
nodejs24-libs-24.15.0-1.amzn2023.0.2.aarch64
nodejs24-24.15.0-1.amzn2023.0.2.aarch64
nodejs24-debugsource-24.15.0-1.amzn2023.0.2.aarch64
noarch:
nodejs24-docs-24.15.0-1.amzn2023.0.2.noarch
nodejs24-npm-11.12.1-1.24.15.0.1.amzn2023.0.2.noarch
src:
nodejs24-24.15.0-1.amzn2023.0.2.src
x86_64:
nodejs24-libs-debuginfo-24.15.0-1.amzn2023.0.2.x86_64
nodejs24-debuginfo-24.15.0-1.amzn2023.0.2.x86_64
nodejs24-full-i18n-24.15.0-1.amzn2023.0.2.x86_64
nodejs24-devel-24.15.0-1.amzn2023.0.2.x86_64
nodejs24-libs-24.15.0-1.amzn2023.0.2.x86_64
nodejs24-24.15.0-1.amzn2023.0.2.x86_64
v8-13.6-devel-13.6.233.17-1.24.15.0.1.amzn2023.0.2.x86_64
nodejs24-debugsource-24.15.0-1.amzn2023.0.2.x86_64