[CLSA-2026:1789050770] alt-nodejs20-nodejs: Fix of CVE-2026-58043
Type:
security
Severity:
Important
Release date:
2026-09-10 14:33:01 UTC
Description:
- CVE-2026-58043: permission: avoid granting radix split nodes so an internal radix-tree branch point created while inserting sibling --allow-fs-read / --allow-fs-write entries (e.g. secret1, secret2, secret3) is no longer mistakenly marked as an explicitly granted path itself (e.g. secret)
CVEs fixed:
Updated packages:
  • alt-nodejs20-nodejs-20.20.2-12.el9.x86_64.rpm
    sha:417d962d43803af7d9cd6a6e76983cf9ed8d71879f41608b95dd332f38b3fcc8
  • alt-nodejs20-nodejs-devel-20.20.2-12.el9.x86_64.rpm
    sha:c49546618b2386bc8a4f8fa366dffda70e10506ec63628c444991e8df9b9b6eb
  • alt-nodejs20-nodejs-docs-20.20.2-12.el9.noarch.rpm
    sha:0fcbc690a26c27bf8d9dcf38e7856e15228c0452f8e356ce26048d706a403482
  • alt-nodejs20-npm-10.8.2-20.20.2.12.el9.x86_64.rpm
    sha:edd53cdfc10901e6fe1801f5dc4ed950c672cb6170d06276a61e0f2d700b5303
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.