Release date:
2026-09-10 14:21:10 UTC
Description:
* SECURITY UPDATE: Permission Model allow-list radix tree grants an
unlisted sibling path when three or more --allow-fs-read /
--allow-fs-write entries share a common prefix
- debian/patches/CVE-2026-58043.patch: in
FSPermission::RadixTree::Node::CreateChild(), stop unconditionally
marking an internal split node as an explicit leaf when a new,
longer allow-list entry is inserted past it, so a node created only
to branch to more specific sibling entries (e.g. secret1, secret2,
secret3) no longer becomes an implicitly granted path of its own
(e.g. secret)
- CVE-2026-58043
Updated packages:
-
alt-nodejs20-docs_20.20.2-10_amd64.deb
sha:4078c0c9be51437951240c02855d085989f4db84
-
alt-nodejs20-nodejs_20.20.2-10_amd64.deb
sha:0e1b184479316d13e59bd8a9217f5c69b1178eb2
-
alt-nodejs20-nodejs-devel_20.20.2-10_amd64.deb
sha:3f457dbab4519a15bb13b3d149f49682a231f495
-
alt-nodejs20-npm_10.8.2-20.20.2-10_amd64.deb
sha:3655e5e7be31b0636bcb307b5ebad213c8e8b311
-
alt-nodejs20-docs_20.20.2-10_arm64.deb
sha:7f0aa00600e9608bbc527e2ff2834e71fcd24c42
-
alt-nodejs20-nodejs_20.20.2-10_arm64.deb
sha:2e341ffc2756bc96c06180a58f68636d9c7b4d83
-
alt-nodejs20-nodejs-devel_20.20.2-10_arm64.deb
sha:ffcb1f7dadc1c08eb6e609b6a4b06584bc0706e0
-
alt-nodejs20-npm_10.8.2-20.20.2-10_arm64.deb
sha:dd61d2531445e70a10489565d5a34f46a6a2c6ea
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.