[CLSA-2026:1789730974] Fix CVE(s): CVE-2026-89157, CVE-2026-89158
Type:
security
Severity:
Critical
Release date:
2026-09-18 11:29:46 UTC
Description:
* EA4D-994: Update to 10.48 version * Bundled Unicode data updated 16.0 -> 17.0, changing what existing patterns match with no soname change: \d gains U+11DE0-U+11DE9, \w and \p{L} gain characters too, and U+0320 no longer matches \p{Latin}. Anything linked against libpcre2-8.so.0 sees this on upgrade without a rebuild; alt-php uses PHP's bundled PCRE2 and is not affected.
Updated packages:
  • alt-pcre2_10.48-1_amd64.deb
    sha:3ac321906e71c47ca9b525d11af5228edf45e10b
  • alt-pcre2-dev_10.48-1_amd64.deb
    sha:dd5f9e01c7e7407d45130cb6830d754a22884bb3
  • alt-pcre2-static_10.48-1_amd64.deb
    sha:148d6dd8098ec827794b8d00ced5a0e9d545e6ae
  • alt-pcre2-tools_10.48-1_amd64.deb
    sha:3374c41898ba61090cd8cdae45a92cafcfeb2c6b
  • alt-pcre2-utf16_10.48-1_amd64.deb
    sha:a39028d4da28b5b1c73b3b163f3410e7dc28e7d6
  • alt-pcre2-utf32_10.48-1_amd64.deb
    sha:3bd9f69300707efc4373acccf77c986ce4be289f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.