SECURITY UPDATE: double free / possible RCE in mod_http2 stream purge
debian/patches/CVE-2026-23918.patch: deduplicate inserts into the
spurge array in modules/http2/h2_mplx.c via a new add_for_purge()
helper to prevent the same h2_stream from being freed twice.