Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.234-225.895 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.234-225.895 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2025-222 Related CVEs: CVE-2025-21703 CVE-2025-21796 CVE-2025-21647 CVE-2025-21702 Upstream summary: In the Linux kernel, the following vulnerability has been resolved: netem: Update sch->q.qlen before qdisc_tree_reduce_backlog() (CVE-2025-21703) Table of contents Symptom & […]

Read more
Amazon Linux 2 — pcs — multiple vulnerabilities (16 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — pcs — multiple vulnerabilities (16 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-3046 Related CVEs: CVE-2025-61770 CVE-2025-61771 CVE-2025-61772 CVE-2025-46727 CVE-2022-30122 CVE-2022-30123 CVE-2018-1000119 CVE-2018-1079  +8 more Upstream summary: Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and […]

Read more
Amazon Linux 2 — apache-commons-vfs — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — apache-commons-vfs — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-2819 Related CVEs: CVE-2025-30474 CVE-2025-27553 Upstream summary: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when a file […]

Read more
Amazon Linux 2 — qt5-qtsvg — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — qt5-qtsvg — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-3051 Related CVEs: CVE-2025-10729 CVE-2024-39936 CVE-2021-28025 CVE-2021-3481 CVE-2023-32573 CVE-2021-45930 Upstream summary: The module will parse a node which is not a child of a structural node. The node will be […]

Read more
Amazon Linux 2 — kernel-livepatch-5.10.233-223.887 — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.233-223.887 — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2025-216 Related CVEs: CVE-2025-21796 CVE-2025-21647 CVE-2025-21702 CVE-2024-56631 CVE-2023-52760 CVE-2024-36899 CVE-2024-49960 CVE-2024-50143 Upstream summary: In the Linux kernel, the following vulnerability has been resolved: nfsd: clear acl_access/acl_default after releasing them (CVE-2025-21796) […]

Read more
Amazon Linux 2 — sssd — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — sssd — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-3050 Related CVEs: CVE-2025-11561 CVE-2022-4254 CVE-2021-3621 CVE-2018-16838 CVE-2019-3811 CVE-2018-10852 Upstream summary: A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux […]

Read more
Amazon Linux 2 — freetype — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — freetype — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-2806 Related CVEs: CVE-2025-23022 CVE-2025-27363 CVE-2020-15999 CVE-2022-27404 CVE-2022-27405 CVE-2022-27406 Upstream summary: FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c. (CVE-2025-23022) An out of bounds write exists in […]

Read more
Amazon Linux 2 — ghostscript — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — ghostscript — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-3018 Related CVEs: CVE-2025-59798 CVE-2025-59799 CVE-2025-59800 CVE-2025-27835 CVE-2025-27836 CVE-2025-27837 CVE-2025-27830 CVE-2025-27831  +12 more Upstream summary: Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c. (CVE-2025-59798) Artifex […]

Read more
Amazon Linux 2 — libreoffice — multiple vulnerabilities (16 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — libreoffice — multiple vulnerabilities (16 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIBREOFFICE-2025-006 Related CVEs: CVE-2025-1080 CVE-2024-7788 CVE-2024-6472 CVE-2018-16858 CVE-2019-9848 CVE-2019-9849 CVE-2019-9850 CVE-2019-9851  +8 more Upstream summary: LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. […]

Read more
Amazon Linux 2 — open-vm-tools — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — open-vm-tools — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-3036 Related CVEs: CVE-2025-41244 CVE-2023-34058 CVE-2023-34059 CVE-2023-20900 CVE-2022-31676 CVE-2025-22247 CVE-2023-20867 Upstream summary: VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative […]

Read more
CHAT