SECURITY UPDATE: double free and possible remote code execution via
HTTP/2 stream double-purge in mod_http2
debian/patches/CVE-2026-23918.patch: prevent double purge of a
stream by introducing add_for_purge() helper that checks for
duplicates before adding to the purge queue in
modules/http2/h2_mplx.c