Release date:
2026-07-31 17:26:46 UTC
Description:
- CVE-2026-48617: gate process.report.writeReport() on the fs.write permission
so diagnostic reports cannot escape the --allow-fs-write allow-list
- CVE-2026-48935: disable FileHandle.utimes() when the Permission Model is
enabled so file timestamps cannot be changed with read-only access
Updated packages:
-
alt-nodejs20-nodejs-20.20.2-6.el10.x86_64.rpm
sha:def2b173cfc39cc2340f7846bec174bdee2dd331fbd0dd31180739eee77463d3
-
alt-nodejs20-nodejs-devel-20.20.2-6.el10.x86_64.rpm
sha:f8d31705c7ae2c413d0dd92ddb9c8aab7ea4fef8d4e861ecdc706d4f166ba890
-
alt-nodejs20-nodejs-docs-20.20.2-6.el10.noarch.rpm
sha:0e995a5e42649ea8867d2408d8ac1fe5d1fdbfc6127b8f72aea619f8c1aece89
-
alt-nodejs20-npm-10.8.2-20.20.2.6.el10.x86_64.rpm
sha:5d84cefd70addd245d02a560e81ddeb5ffb45cbd0eaaf50718aaeef91626d029
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.