[CLSA-2026:1789052628] alt-nodejs20-nodejs: Fix of CVE-2026-58043
Type:
security
Severity:
Important
Release date:
2026-09-10 15:04:04 UTC
Description:
- CVE-2026-58043: permission: avoid granting radix split nodes so an internal radix-tree branch point created while inserting sibling --allow-fs-read / --allow-fs-write entries (e.g. secret1, secret2, secret3) is no longer mistakenly marked as an explicitly granted path itself (e.g. secret)
CVEs fixed:
Updated packages:
  • alt-nodejs20-nodejs-20.20.2-12.el7.x86_64.rpm
    sha:a09f606d9fd83c9873ce8e4e8d20d1fe338619ff5ac73ef9f4b93f49109107d3
  • alt-nodejs20-nodejs-devel-20.20.2-12.el7.x86_64.rpm
    sha:79bffaec94a3cf03a20c50449886359af2a961ff2ee77db8450141f614653c20
  • alt-nodejs20-nodejs-docs-20.20.2-12.el7.noarch.rpm
    sha:ef2f9fd48925626998a7577f366a16c7c305672e6312a76ac1ae0f9496971c1a
  • alt-nodejs20-npm-10.8.2-20.20.2.12.el7.x86_64.rpm
    sha:4cc4b0763d3182320183a332c1afe86534be93f787afa5b655bb8a823684967d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.