Release date:
2026-07-31 15:40:58 UTC
Description:
- CVE-2026-48617: gate process.report.writeReport() on the fs.write permission
so diagnostic reports cannot escape the --allow-fs-write allow-list
- CVE-2026-48935: disable FileHandle.utimes() when the Permission Model is
enabled so file timestamps cannot be changed with read-only access
Updated packages:
-
alt-nodejs20-nodejs-20.20.2-6.el7.x86_64.rpm
sha:634d4f8bf79143cea17a6452b281a642db8ba0503d98a9e5d4653037c119459e
-
alt-nodejs20-nodejs-devel-20.20.2-6.el7.x86_64.rpm
sha:205bc5c7945749e38870797a0d8f6c7d3f7c9ca0caff4b04d7b94b2143ab1f6a
-
alt-nodejs20-nodejs-docs-20.20.2-6.el7.noarch.rpm
sha:4b0031d8dcdeff26a1ed68c38937791ceccf44dbece54ba5f97dc854960b592f
-
alt-nodejs20-npm-10.8.2-20.20.2.6.el7.x86_64.rpm
sha:d77bca906c15a862c2b18bb91f7949cde68bd4369b612b6ab1aa85037d83583c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.