[CLSA-2026:1788184429] Fix CVE(s): CVE-2026-58040
Type:
security
Severity:
Moderate
Release date:
2026-08-31 13:54:00 UTC
Description:
* resync the alt-nodejs18-npm changelog with the package revision: the npm changelog was left at 10.8.2-18.20.8.17 while debian/changelog had advanced to 18.20.8-19, so the npm binary package shipped a revision suffix that no longer matched the runtime it ships with. Both changelogs are bumped to revision 20 rather than only fast-forwarding the npm one, because an out-of-sync revision has already been released, so the npm version has to move forward on a revision that is still free * buildsys-pre-build: assert that the revision suffix in debian/alt-nodejs*-npm.changelog matches the debian/changelog version, not just that the npm upstream version matches deps/npm/package.json, so a forgotten npm changelog bump fails the build instead of silently shipping a stale npm revision
CVEs fixed:
Updated packages:
  • alt-nodejs18-docs_18.20.8-20_amd64.deb
    sha:b222e12e5df8167a1a39d593528735fab62edcd3
  • alt-nodejs18-nodejs_18.20.8-20_amd64.deb
    sha:8e85175c211924122f0e8a9f49c654f5536ebbef
  • alt-nodejs18-nodejs-devel_18.20.8-20_amd64.deb
    sha:68f85123b5402d9c51fc436a079f720d76ce4af4
  • alt-nodejs18-npm_10.8.2-18.20.8.20_amd64.deb
    sha:1dccc46bbad767d676bfbc3aa689c4db7b78228e
  • alt-nodejs18-docs_18.20.8-20_arm64.deb
    sha:18a40befb3846dc301fa114ad057fabc4ea92b6e
  • alt-nodejs18-nodejs_18.20.8-20_arm64.deb
    sha:08659d7db2bbadc096eb512783038b4ed659be14
  • alt-nodejs18-nodejs-devel_18.20.8-20_arm64.deb
    sha:7c8f3a3f181d79375a577408a7aaddab5aa3e2f7
  • alt-nodejs18-npm_10.8.2-18.20.8.20_arm64.deb
    sha:70021ecfdcfe33a36185580d236d561a95826013
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.