[CLSA-2026:1789736894] Fix CVE(s): CVE-2026-89157, CVE-2026-89158
Type:
security
Severity:
Critical
Release date:
2026-09-18 13:08:26 UTC
Description:
* EA4D-994: Update to 10.48 version * Bundled Unicode data updated 16.0 -> 17.0, changing what existing patterns match with no soname change: \d gains U+11DE0-U+11DE9, \w and \p{L} gain characters too, and U+0320 no longer matches \p{Latin}. Anything linked against libpcre2-8.so.0 sees this on upgrade without a rebuild; alt-php uses PHP's bundled PCRE2 and is not affected.
Updated packages:
  • alt-pcre2_10.48-1_amd64.deb
    sha:9f6457801c5dc9e7be832e2d76aa43eeed902655
  • alt-pcre2-dev_10.48-1_amd64.deb
    sha:43ae4877c0e6fc1e3db69c4ccf08ed30aaeb5a61
  • alt-pcre2-static_10.48-1_amd64.deb
    sha:8cc36d0482e50fcff78d6ef5d6ed64dcd25afa0d
  • alt-pcre2-tools_10.48-1_amd64.deb
    sha:8a18ac3116d000dc4c66e7d1cc445b9d617e4619
  • alt-pcre2-utf16_10.48-1_amd64.deb
    sha:e56149c2b9c7ea9b568489e9536c64d501676093
  • alt-pcre2-utf32_10.48-1_amd64.deb
    sha:7633e2584f2a575d3f72a308aef5daeeeff88398
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.