Amazon Linux 2

Amazon Linux 2 — perl-FCGI — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — perl-FCGI — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-2880 Related CVEs: CVE-2025-23016 CVE-2025-40907 Upstream summary: FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library. The included FastCGI library is […]

Read more
Amazon Linux 2 — kernel-livepatch-4.14.355-275.603 — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-4.14.355-275.603 — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2025-236 Related CVEs: CVE-2025-21811 CVE-2025-21858 CVE-2025-21920 CVE-2024-47757 CVE-2024-49882 CVE-2024-50036 CVE-2024-50264 CVE-2024-50301  +4 more Upstream summary: In the Linux kernel, the following vulnerability has been resolved: nilfs2: protect access to buffers […]

Read more
Amazon Linux 2 — libsodium — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — libsodium — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2PHP8.2-2026-010 Related CVEs: CVE-2025-69277 Upstream summary: libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point […]

Read more
Amazon Linux 2 — kernel-livepatch-5.10.237-230.948 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.237-230.948 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2025-259 Related CVEs: CVE-2022-49935 CVE-2025-38037 Upstream summary: In the Linux kernel, the following vulnerability has been resolved: dma-buf/dma-resv: check if the new fence is really later (CVE-2022-49935) Table of contents […]

Read more
Amazon Linux 2 — qt5 — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — qt5 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2024-2675 Related CVEs: CVE-2024-39936 Upstream summary: An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. […]

Read more
Amazon Linux 2 — libuv — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — libuv — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2021-1581 Related CVEs: CVE-2020-8201 CVE-2020-8251 CVE-2024-24806 CVE-2021-22918 Upstream summary: Node.js A flaw was found in Node.js 14.x, in versions before 14.11, where it is vulnerable to a denial of service […]

Read more
Amazon Linux 2 — rsync — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — rsync — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-2731 Related CVEs: CVE-2024-12085 CVE-2024-12086 CVE-2024-12087 CVE-2024-12088 CVE-2024-12747 CVE-2022-29154 CVE-2025-10158 CVE-2022-37434 Upstream summary: A flaw was found in the rsync daemon which could be triggered when rsync compares file checksums. […]

Read more
Amazon Linux 2 — kernel-livepatch-5.10.216-204.855 — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.216-204.855 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2024-178 Related CVEs: CVE-2024-39480 Upstream summary: In the Linux kernel, the following vulnerability has been resolved: kdb: Fix buffer overflow during tab-complete (CVE-2024-39480) Table of contents Symptom & Impact Environment […]

Read more
Amazon Linux 2 — qt5-qtbase — multiple vulnerabilities (18 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — qt5-qtbase — multiple vulnerabilities (18 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-3102 Related CVEs: CVE-2025-12385 CVE-2024-39936 CVE-2023-37369 CVE-2020-17507 CVE-2023-51714 CVE-2022-25634 CVE-2023-38197 CVE-2023-32762  +10 more Upstream summary: Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability […]

Read more
CHAT