[CLSA-2026:1789051338] alt-nodejs20-nodejs: Fix of CVE-2026-58043
Type:
security
Severity:
Important
Release date:
2026-09-10 14:42:31 UTC
Description:
- CVE-2026-58043: permission: avoid granting radix split nodes so an internal radix-tree branch point created while inserting sibling --allow-fs-read / --allow-fs-write entries (e.g. secret1, secret2, secret3) is no longer mistakenly marked as an explicitly granted path itself (e.g. secret)
CVEs fixed:
Updated packages:
  • alt-nodejs20-nodejs-20.20.2-12.el8.x86_64.rpm
    sha:2e4caebfbca6b8691dcf0fd70d7a9aa30cf6238e0627c6fd07549e6c610cf77b
  • alt-nodejs20-nodejs-devel-20.20.2-12.el8.x86_64.rpm
    sha:f229db6b85611cc68ad02b9e21f9d273119ed925a30feb713de32e291c560c5f
  • alt-nodejs20-nodejs-docs-20.20.2-12.el8.noarch.rpm
    sha:42e9c1c07c6ae17b40e98a2d35bdf4d55877c6c11c978db6c996012f7dbc7f86
  • alt-nodejs20-npm-10.8.2-20.20.2.12.el8.x86_64.rpm
    sha:e21d5e9616a9221af0f6776a112fb65d796d823d477abc2f29f4109a4fd35deb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.