[CLSA-2026:1789737565] Fix CVE(s): CVE-2026-89157, CVE-2026-89158
Type:
security
Severity:
Critical
Release date:
2026-09-18 13:19:38 UTC
Description:
* EA4D-994: Update to 10.48 version * Bundled Unicode data updated 16.0 -> 17.0, changing what existing patterns match with no soname change: \d gains U+11DE0-U+11DE9, \w and \p{L} gain characters too, and U+0320 no longer matches \p{Latin}. Anything linked against libpcre2-8.so.0 sees this on upgrade without a rebuild; alt-php uses PHP's bundled PCRE2 and is not affected.
Updated packages:
  • alt-pcre2_10.48-1_amd64.deb
    sha:d511e311bd4389fe954d64092e84b269ed31831d
  • alt-pcre2-dev_10.48-1_amd64.deb
    sha:c3ecb1dbee8afef4ebf98a61936319693303fb74
  • alt-pcre2-static_10.48-1_amd64.deb
    sha:ad439f99b3cdcf1807d79c3af406418508bbf63a
  • alt-pcre2-tools_10.48-1_amd64.deb
    sha:d6079e5a99de4c7fc9738c447ac7cc955fcfe0f5
  • alt-pcre2-utf16_10.48-1_amd64.deb
    sha:aaa4c3976aa3e67d86d8f8fe771d74fac00dfdb6
  • alt-pcre2-utf32_10.48-1_amd64.deb
    sha:c0e907a68b04f7c790cfe6de426884cc66882628
  • alt-pcre2_10.48-1_arm64.deb
    sha:c465da4662854c9358be64d4d6c8be5449ddde7b
  • alt-pcre2-dev_10.48-1_arm64.deb
    sha:13e50954ba6bd8e33750a21b59699334258199a6
  • alt-pcre2-static_10.48-1_arm64.deb
    sha:f929b1ce1acabe39130c4249102e735ca5317b48
  • alt-pcre2-tools_10.48-1_arm64.deb
    sha:d1f11ed42d4c7a902d7a818cca1d847161f51ec6
  • alt-pcre2-utf16_10.48-1_arm64.deb
    sha:71e2947df729761aa154f72e1cae11eaac8fc75a
  • alt-pcre2-utf32_10.48-1_arm64.deb
    sha:386a4936de6868282276556a96a7335b19ef63de
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.