[CLSA-2026:1789051982] Fix CVE(s): CVE-2026-58043
Type:
security
Severity:
Important
Release date:
2026-09-10 14:53:17 UTC
Description:
* SECURITY UPDATE: Permission Model allow-list radix tree grants an unlisted sibling path when three or more --allow-fs-read / --allow-fs-write entries share a common prefix - debian/patches/CVE-2026-58043.patch: in FSPermission::RadixTree::Node::CreateChild(), stop unconditionally marking an internal split node as an explicit leaf when a new, longer allow-list entry is inserted past it, so a node created only to branch to more specific sibling entries (e.g. secret1, secret2, secret3) no longer becomes an implicitly granted path of its own (e.g. secret) - CVE-2026-58043
CVEs fixed:
Updated packages:
  • alt-nodejs20-docs_20.20.2-10_amd64.deb
    sha:93f49b300478cb403e6dc08d8164ff1c357110fb
  • alt-nodejs20-nodejs_20.20.2-10_amd64.deb
    sha:aec0fc12c73d32ca4ec3dfa46b6ee88ecf4fbf66
  • alt-nodejs20-nodejs-devel_20.20.2-10_amd64.deb
    sha:8ba1723e33fef365bb52ece2229ee3bea11eb6f7
  • alt-nodejs20-npm_10.8.2-20.20.2-10_amd64.deb
    sha:c562e425fba22cb469278852c953fd216b35d16a
  • alt-nodejs20-docs_20.20.2-10_arm64.deb
    sha:611b867d7e6d1ff470fa17cd1d66663b18f14615
  • alt-nodejs20-nodejs_20.20.2-10_arm64.deb
    sha:90378eed6792d13c7b3b1a0da9def5b6732e9554
  • alt-nodejs20-nodejs-devel_20.20.2-10_arm64.deb
    sha:da9ea92764ccca048de14f66bc66913a1d7bcea8
  • alt-nodejs20-npm_10.8.2-20.20.2-10_arm64.deb
    sha:19aed8cce4c66a917d810f2dbac222559e64e81a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.