Amazon Linux 2

Amazon Linux 2 — aws-cfn-bootstrap — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — aws-cfn-bootstrap — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-3104 Related CVEs: CVE-2024-13176 CVE-2024-47081 CVE-2025-9230 CVE-2024-35195 Upstream summary: Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: […]

Read more
Amazon Linux 2 — kernel-livepatch-5.10.238-231.953 — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.238-231.953 — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2025-268 Related CVEs: CVE-2025-38527 CVE-2025-39677 CVE-2025-39691 CVE-2025-39730 CVE-2025-38386 CVE-2022-49935 Upstream summary: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free in cifs_oplock_break (CVE-2025-38527) In the […]

Read more
Amazon Linux 2 — kernel-livepatch-5.10.227-219.884 — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.227-219.884 — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2025-196 Related CVEs: CVE-2023-52760 CVE-2024-36899 CVE-2024-49960 CVE-2024-49996 CVE-2024-50055 CVE-2024-50083 CVE-2024-50121 CVE-2024-50143  +4 more Upstream summary: In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix slab-use-after-free in gfs2_qd_dealloc […]

Read more
Amazon Linux 2 — pam — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — pam — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-3057 Related CVEs: CVE-2025-6020 CVE-2025-8941 CVE-2024-10041 CVE-2024-22365 Upstream summary: A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks […]

Read more
Amazon Linux 2 — kernel-livepatch-5.10.201-191.748 — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.201-191.748 — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2024-167 Related CVEs: CVE-2023-6040 CVE-2023-6606 CVE-2023-6817 CVE-2023-6932 CVE-2024-0565 CVE-2024-0646 CVE-2024-23849 Upstream summary: An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables: Reject tables of unsupported […]

Read more
Amazon Linux 2 — udisks2 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — udisks2 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-2992 Related CVEs: CVE-2025-8067 CVE-2025-6019 CVE-2018-17336 CVE-2021-3802 Upstream summary: A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the D-BUS system. […]

Read more
Amazon Linux 2 — vsftpd — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — vsftpd — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2026-3176 Related CVEs: CVE-2025-14242 CVE-2021-3618 Upstream summary: A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls command parameter […]

Read more
Amazon Linux 2 — R — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — R — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2R3.4-2024-001 Related CVEs: CVE-2024-27322 Upstream summary: Deserialization of untrusted data can occur in the R statistical programming language, on any version starting at 1.4.0 up to and not including 4.4.0, […]

Read more
Amazon Linux 2 — kernel-livepatch-4.14.355-277.647 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-4.14.355-277.647 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2025-253 Related CVEs: CVE-2022-49935 CVE-2023-53137 CVE-2025-21811 Upstream summary: In the Linux kernel, the following vulnerability has been resolved: dma-buf/dma-resv: check if the new fence is really later (CVE-2022-49935) Table of […]

Read more
Amazon Linux 2 — zziplib — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — zziplib — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2024-2713 Related CVEs: CVE-2024-39134 CVE-2020-18770 CVE-2018-17828 CVE-2018-16548 CVE-2018-6541 CVE-2018-7725 CVE-2018-7726 CVE-2018-7727 Upstream summary: A Stack Buffer Overflow vulnerability in zziplibv 0.13.77 allows attackers to cause a denial of service via […]

Read more
CHAT