[CLSA-2026:1785517985] alt-nodejs20-nodejs: Fix of 7 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-07-31 17:13:21 UTC
Description:
- CVE-2026-48617: gate process.report.writeReport() on the fs.write permission so diagnostic reports cannot escape the --allow-fs-write allow-list - CVE-2026-48935: disable FileHandle.utimes() when the Permission Model is enabled so file timestamps cannot be changed with read-only access
Updated packages:
  • alt-nodejs20-nodejs-20.20.2-6.el9.x86_64.rpm
    sha:6b24373f3b40b53397d7f07be4fe9be94d7ecddf87802bb6337d20db063d86ce
  • alt-nodejs20-nodejs-devel-20.20.2-6.el9.x86_64.rpm
    sha:e02a1004001324b85941fa7cc5150a6b10a54bda75d92eda88044124321ba2ca
  • alt-nodejs20-nodejs-docs-20.20.2-6.el9.noarch.rpm
    sha:ab3eeaab533e2756fbb74f05b6b31ffafacaa496bee32bc3c37188fcc1047246
  • alt-nodejs20-npm-10.8.2-20.20.2.6.el9.x86_64.rpm
    sha:2f05f9432d29b9ba807862d66cbf840fb6c3572c92c6befe916c76b31995daa0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.