[CLSA-2026:1788262747] Fix CVE(s): CVE-2026-58040
Type:
security
Severity:
Moderate
Release date:
2026-09-01 11:39:25 UTC
Description:
* resync the alt-nodejs23-npm changelog with the package revision: the npm changelog was left at 10.9.2-23.11.1.17 while debian/changelog had advanced to 23.11.1-19, so the npm binary package shipped a revision suffix that no longer matched the runtime it ships with. Both changelogs are bumped to revision 20 rather than only fast-forwarding the npm one, because an out-of-sync revision has already been released, so the npm version has to move forward on a revision that is still free * buildsys-pre-build: assert that the revision suffix in debian/alt-nodejs*-npm.changelog matches the debian/changelog version, not just that the npm upstream version matches deps/npm/package.json, so a forgotten npm changelog bump fails the build instead of silently shipping a stale npm revision
CVEs fixed:
Updated packages:
  • alt-nodejs23-docs_23.11.1-20_amd64.deb
    sha:0f8b0a5db8838fa238d6809ca6392b035c0bf94b
  • alt-nodejs23-nodejs_23.11.1-20_amd64.deb
    sha:bcdda1eb5b709e83f9530e1a83cf9e4139943af0
  • alt-nodejs23-nodejs-devel_23.11.1-20_amd64.deb
    sha:1488e0c47c420e4d3bf7e15026a84d0c43e210ff
  • alt-nodejs23-npm_10.9.2-23.11.1.20_amd64.deb
    sha:2253541413e918e91f8acbbd51bbbfc821fe0d36
  • alt-nodejs23-docs_23.11.1-20_arm64.deb
    sha:3cc64bb5baf4ae16107365b1bdfbd1e7d67d3c03
  • alt-nodejs23-nodejs_23.11.1-20_arm64.deb
    sha:ae4c85cb517dbde722a644374b1993cf3d73dfc4
  • alt-nodejs23-nodejs-devel_23.11.1-20_arm64.deb
    sha:0f693ec50a0cb7d8665b242f869ad11da07084b3
  • alt-nodejs23-npm_10.9.2-23.11.1.20_arm64.deb
    sha:f94c619968bbd17227cf8603f84aac12e65730c7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.