[CLSA-2026:1785518338] alt-nodejs20-nodejs: Fix of 7 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-07-31 17:19:15 UTC
Description:
- CVE-2026-48617: gate process.report.writeReport() on the fs.write permission so diagnostic reports cannot escape the --allow-fs-write allow-list - CVE-2026-48935: disable FileHandle.utimes() when the Permission Model is enabled so file timestamps cannot be changed with read-only access
Updated packages:
  • alt-nodejs20-nodejs-20.20.2-6.el8.x86_64.rpm
    sha:4ab722090538a2f7551aad44ea3e7332036c0fa3103cefead2ad89204cfd56e4
  • alt-nodejs20-nodejs-devel-20.20.2-6.el8.x86_64.rpm
    sha:722eda21830fbdb6fb3e07c59028d5bc3c83d20a584a6857f6b571de287b02ee
  • alt-nodejs20-nodejs-docs-20.20.2-6.el8.noarch.rpm
    sha:c3b4b46c135ec9bf98ed5a19ffd4d5e6216118537a451203ef9f5962b6c648ef
  • alt-nodejs20-npm-10.8.2-20.20.2.6.el8.x86_64.rpm
    sha:6d3cfe922bfb33d8c967ace6b024c1f9d3b4b53de31895af548bbbd23f590c08
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.