[CLSA-2026:1772033654] Fix CVE(s): CVE-2025-55132
Type:
security
Severity:
None
Release date:
2026-02-26 16:27:37 UTC
Description:
* SECURITY UPDATE: File descriptor metadata bypass in permission model - debian/patches/CVE-2025-55132.patch: disable futimes, fdatasync, and fsync APIs when permission model is enabled to prevent metadata updates via read-only file descriptors - CVE-2025-55132
Updated packages:
  • alt-nodejs23-docs_23.11.1-5_amd64.deb
    sha:b28c3c647cb771720a4ebdf6315f12002cf69b81
  • alt-nodejs23-nodejs_23.11.1-5_amd64.deb
    sha:20a13f38230c938baf7048407812fde7ce911521
  • alt-nodejs23-nodejs-devel_23.11.1-5_amd64.deb
    sha:b970f6dcae79cad0ecd5e42e1a89455623d16618
  • alt-nodejs23-npm_10.9.2-23.11.1.5_amd64.deb
    sha:ebcec40e72086aecdb002a371b5ffe970bab6833
  • alt-nodejs23-docs_23.11.1-5_arm64.deb
    sha:09c34670064b57336f97a645ffbdd6bdb1c6cc6d
  • alt-nodejs23-nodejs_23.11.1-5_arm64.deb
    sha:473723831b474df18b3821278f6d0dd9decc7513
  • alt-nodejs23-nodejs-devel_23.11.1-5_arm64.deb
    sha:84a1c93853780d17530bc697ba0a6c93c99a3e48
  • alt-nodejs23-npm_10.9.2-23.11.1.5_arm64.deb
    sha:9a724582ab2842cd1539c584cd8c16772f3cf2f5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.