SECURITY UPDATE: double free / possible RCE in mod_http2 stream purge
debian/patches/CVE-2026-23918.patch: deduplicate inserts into the
spurge array in modules/http2/h2mplx.c via a new addforpurge()
helper to prevent the same h2stream from being freed twice.