[CLSA-2026:1789737927] Fix CVE(s): CVE-2026-89157, CVE-2026-89158
Type:
security
Severity:
Critical
Release date:
2026-09-18 13:25:40 UTC
Description:
* EA4D-994: Update to 10.48 version * Bundled Unicode data updated 16.0 -> 17.0, changing what existing patterns match with no soname change: \d gains U+11DE0-U+11DE9, \w and \p{L} gain characters too, and U+0320 no longer matches \p{Latin}. Anything linked against libpcre2-8.so.0 sees this on upgrade without a rebuild; alt-php uses PHP's bundled PCRE2 and is not affected.
Updated packages:
  • alt-pcre2_10.48-1_amd64.deb
    sha:a61a036a9f63c1fce52029769785494249315bb1
  • alt-pcre2-dev_10.48-1_amd64.deb
    sha:0db48a9debb8974b78009fd7de6a4c3b22e8ad5f
  • alt-pcre2-static_10.48-1_amd64.deb
    sha:a92bfc9331e8533edd366052ccbafd7501445246
  • alt-pcre2-tools_10.48-1_amd64.deb
    sha:bafc51c0c8b3b29b4c8bfd5c285e8c1b17139106
  • alt-pcre2-utf16_10.48-1_amd64.deb
    sha:7b39244d9a32b6cdb94f0358bef2b54e35c3b8e8
  • alt-pcre2-utf32_10.48-1_amd64.deb
    sha:d4256cf0b70c975ef0e7d160313fe3013388df78
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.