[CLSA-2026:1785498299] Fix of 7 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-07-31 11:45:15 UTC
Description:
* SECURITY UPDATE: Permission Model bypass via process.report.writeReport() path misvalidation - debian/patches/CVE-2026-48617.patch: gate writeReport() in lib/internal/process/report.js on permission.has('fs.write', ...) for the supplied file or the current working directory, throwing ERR_ACCESS_DENIED instead of writing a diagnostic report outside the --allow-fs-write allow-list - CVE-2026-48617 * SECURITY UPDATE: Permission Model bypass via FileHandle.utimes() in the promises API - debian/patches/CVE-2026-48935.patch: throw ERR_ACCESS_DENIED from futimes() in lib/internal/fs/promises.js when the Permission Model is enabled, so file timestamps can no longer be modified through a read-only FileHandle - CVE-2026-48935
Updated packages:
  • alt-nodejs20-docs_20.20.2-6_amd64.deb
    sha:080780b1ca19cc34fe04d82d7c30e0b0d863cc84
  • alt-nodejs20-nodejs_20.20.2-6_amd64.deb
    sha:2ebe993137c730d50d4d7000e9dcf6d612f2027a
  • alt-nodejs20-nodejs-devel_20.20.2-6_amd64.deb
    sha:258e823f49545211bb27f8e3c38c11bde5a0a4e2
  • alt-nodejs20-npm_10.8.2-20.20.2-6_amd64.deb
    sha:3da1d4ecd68932dcd5d9daeceb40f0a0aa86bf56
  • alt-nodejs20-docs_20.20.2-6_arm64.deb
    sha:fce61cc8a4bfe7c14236034c1f80162b3b16cf80
  • alt-nodejs20-nodejs_20.20.2-6_arm64.deb
    sha:d8b7b764bbb654fdb3486c295c55fa2250077a88
  • alt-nodejs20-nodejs-devel_20.20.2-6_arm64.deb
    sha:ec92bbdf5d8efe159a80005e33e5fb7edda35a4c
  • alt-nodejs20-npm_10.8.2-20.20.2-6_arm64.deb
    sha:e90ff279dc58270e274e4b6497104191c1aa77fb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.