[CLSA-2026:1789736756] Fix CVE(s): CVE-2026-89157, CVE-2026-89158
Type:
security
Severity:
Critical
Release date:
2026-09-18 13:06:08 UTC
Description:
* EA4D-994: Update to 10.48 version * Bundled Unicode data updated 16.0 -> 17.0, changing what existing patterns match with no soname change: \d gains U+11DE0-U+11DE9, \w and \p{L} gain characters too, and U+0320 no longer matches \p{Latin}. Anything linked against libpcre2-8.so.0 sees this on upgrade without a rebuild; alt-php uses PHP's bundled PCRE2 and is not affected.
Updated packages:
  • alt-pcre2_10.48-1_amd64.deb
    sha:d749327d3e2dbd05411afe7f6556778361032504
  • alt-pcre2-dev_10.48-1_amd64.deb
    sha:f308ef7246660f02a6603563f4085c8475d6af46
  • alt-pcre2-static_10.48-1_amd64.deb
    sha:734df38c54958328ffac8928806e5dcda0a3433a
  • alt-pcre2-tools_10.48-1_amd64.deb
    sha:97c4f6d9f6d00a816a2d40ce65ac3615263fd54d
  • alt-pcre2-utf16_10.48-1_amd64.deb
    sha:ef1a23177de3f43828bcf8b7c7be48510264021b
  • alt-pcre2-utf32_10.48-1_amd64.deb
    sha:5616ad3d5b66ef0f0cb1b4644cde3e8619c2c3b8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.