Release date:
2026-09-11 15:57:22 UTC
Description:
* SECURITY UPDATE: Permission Model allow-list radix tree grants an
unlisted sibling path when three or more --allow-fs-read /
--allow-fs-write entries share a common prefix
- debian/patches/CVE-2026-58043.patch: in
FSPermission::RadixTree::Node::CreateChild(), stop unconditionally
marking an internal split node as an explicit leaf when a new,
longer allow-list entry is inserted past it, so a node created only
to branch to more specific sibling entries (e.g. secret1, secret2,
secret3) no longer becomes an implicitly granted path of its own
(e.g. secret)
- CVE-2026-58043
Updated packages:
-
alt-nodejs20-docs_20.20.2-10_amd64.deb
sha:cae2c16b3d14a10d0fd2e64b464388e1e2eff436
-
alt-nodejs20-nodejs_20.20.2-10_amd64.deb
sha:092ff1c66573126921e42f48a2d381b6c610638f
-
alt-nodejs20-nodejs-devel_20.20.2-10_amd64.deb
sha:10abdfcc0b42b74e0f5a135f04a3885b3338e63f
-
alt-nodejs20-npm_10.8.2-20.20.2-10_amd64.deb
sha:6cf3c22e9c0a8af7ef300168af85c45010ad2d83
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.