[CLSA-2026:1789737730] Fix CVE(s): CVE-2026-89157, CVE-2026-89158
Type:
security
Severity:
Critical
Release date:
2026-09-18 13:22:23 UTC
Description:
* EA4D-994: Update to 10.48 version * Bundled Unicode data updated 16.0 -> 17.0, changing what existing patterns match with no soname change: \d gains U+11DE0-U+11DE9, \w and \p{L} gain characters too, and U+0320 no longer matches \p{Latin}. Anything linked against libpcre2-8.so.0 sees this on upgrade without a rebuild; alt-php uses PHP's bundled PCRE2 and is not affected.
Updated packages:
  • alt-pcre2_10.48-1_amd64.deb
    sha:4df08319187d5a33a213c7513d01eefd0e8c4827
  • alt-pcre2-dev_10.48-1_amd64.deb
    sha:4800549589c810326b9528b8fb0caebbcff66d6a
  • alt-pcre2-static_10.48-1_amd64.deb
    sha:8ba1c884b156d6b970eb660f2245c334933051c5
  • alt-pcre2-tools_10.48-1_amd64.deb
    sha:04be11c107560f7f774ce0c0891c3307dffb7c1d
  • alt-pcre2-utf16_10.48-1_amd64.deb
    sha:c60294df46ab84c3b5b185028add0494f7f27782
  • alt-pcre2-utf32_10.48-1_amd64.deb
    sha:c180a5cc08951b6c5c562d51ef4bab2fb6332750
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.