Release date:
2026-07-31 12:20:20 UTC
Description:
* SECURITY UPDATE: Permission Model bypass via process.report.writeReport()
path misvalidation
- debian/patches/CVE-2026-48617.patch: gate writeReport() in
lib/internal/process/report.js on permission.has('fs.write', ...) for
the supplied file or the current working directory, throwing
ERR_ACCESS_DENIED instead of writing a diagnostic report outside the
--allow-fs-write allow-list
- CVE-2026-48617
* SECURITY UPDATE: Permission Model bypass via FileHandle.utimes() in the
promises API
- debian/patches/CVE-2026-48935.patch: throw ERR_ACCESS_DENIED from
futimes() in lib/internal/fs/promises.js when the Permission Model is
enabled, so file timestamps can no longer be modified through a
read-only FileHandle
- CVE-2026-48935
Updated packages:
-
alt-nodejs20-docs_20.20.2-6_amd64.deb
sha:080780b1ca19cc34fe04d82d7c30e0b0d863cc84
-
alt-nodejs20-nodejs_20.20.2-6_amd64.deb
sha:2fb6059bec1a9d27c7e686d476e00a85d61e9542
-
alt-nodejs20-nodejs-devel_20.20.2-6_amd64.deb
sha:3326d6df8fc4fe20afb536159060642eb652a4b9
-
alt-nodejs20-npm_10.8.2-20.20.2-6_amd64.deb
sha:3da1d4ecd68932dcd5d9daeceb40f0a0aa86bf56
-
alt-nodejs20-docs_20.20.2-6_arm64.deb
sha:fce61cc8a4bfe7c14236034c1f80162b3b16cf80
-
alt-nodejs20-nodejs_20.20.2-6_arm64.deb
sha:1f643675048f4c8685d3ea45de174fc2bdb5806b
-
alt-nodejs20-nodejs-devel_20.20.2-6_arm64.deb
sha:5784b86f63b1d19ea983ece5c06038348e0f310b
-
alt-nodejs20-npm_10.8.2-20.20.2-6_arm64.deb
sha:e90ff279dc58270e274e4b6497104191c1aa77fb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.