Release date:
2026-07-31 17:13:21 UTC
Description:
- CVE-2026-48617: gate process.report.writeReport() on the fs.write permission
so diagnostic reports cannot escape the --allow-fs-write allow-list
- CVE-2026-48935: disable FileHandle.utimes() when the Permission Model is
enabled so file timestamps cannot be changed with read-only access
Updated packages:
-
alt-nodejs20-nodejs-20.20.2-6.el9.x86_64.rpm
sha:6b24373f3b40b53397d7f07be4fe9be94d7ecddf87802bb6337d20db063d86ce
-
alt-nodejs20-nodejs-devel-20.20.2-6.el9.x86_64.rpm
sha:e02a1004001324b85941fa7cc5150a6b10a54bda75d92eda88044124321ba2ca
-
alt-nodejs20-nodejs-docs-20.20.2-6.el9.noarch.rpm
sha:ab3eeaab533e2756fbb74f05b6b31ffafacaa496bee32bc3c37188fcc1047246
-
alt-nodejs20-npm-10.8.2-20.20.2.6.el9.x86_64.rpm
sha:2f05f9432d29b9ba807862d66cbf840fb6c3572c92c6befe916c76b31995daa0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.