[CLSA-2026:1789731116] Fix CVE(s): CVE-2026-89157, CVE-2026-89158
Type:
security
Severity:
Critical
Release date:
2026-09-18 11:32:08 UTC
Description:
* EA4D-994: Update to 10.48 version * Bundled Unicode data updated 16.0 -> 17.0, changing what existing patterns match with no soname change: \d gains U+11DE0-U+11DE9, \w and \p{L} gain characters too, and U+0320 no longer matches \p{Latin}. Anything linked against libpcre2-8.so.0 sees this on upgrade without a rebuild; alt-php uses PHP's bundled PCRE2 and is not affected.
Updated packages:
  • alt-pcre2_10.48-1_amd64.deb
    sha:4edcaf029c39fc12546b6c72751a10fe1aeeda3a
  • alt-pcre2-dev_10.48-1_amd64.deb
    sha:f308ef7246660f02a6603563f4085c8475d6af46
  • alt-pcre2-static_10.48-1_amd64.deb
    sha:d1b82281d80988576a7e63369487767f31233d2b
  • alt-pcre2-tools_10.48-1_amd64.deb
    sha:36bfb8dfaf24c115ec332cdadbcb4a0071025bd0
  • alt-pcre2-utf16_10.48-1_amd64.deb
    sha:72f1f65f7726f67a07948be84ebfc254f43deb72
  • alt-pcre2-utf32_10.48-1_amd64.deb
    sha:0e27697521861c53dfc5355700c0f62c7aaaec36
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.