Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.238-234.956 — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.238-234.956 — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2025-270 Related CVEs: CVE-2025-38527 CVE-2025-39677 CVE-2025-39691 CVE-2025-39730 CVE-2025-38386 CVE-2022-49935 Upstream summary: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free in cifs_oplock_break (CVE-2025-38527) In the […]

Read more
Amazon Linux 2 — xerces-c — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — xerces-c — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2023-2327 Related CVEs: CVE-2023-37536 CVE-2018-1311 CVE-2024-23807 CVE-2016-4463 Upstream summary: An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request. (CVE-2023-37536) Table […]

Read more
Amazon Linux 2 — libxslt — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — libxslt — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-2966 Related CVEs: CVE-2025-7424 CVE-2024-55549 CVE-2025-24855 CVE-2023-40403 CVE-2019-11068 CVE-2019-18197 Upstream summary: A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and […]

Read more
Amazon Linux 2 — qt5-qtimageformats — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — qt5-qtimageformats — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2024-2671 Related CVEs: CVE-2024-39936 CVE-2023-4863 CVE-2018-25011 CVE-2018-25014 CVE-2020-36328 CVE-2020-36329 Upstream summary: An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and […]

Read more
Amazon Linux 2 — perl-Authen-SASL — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — perl-Authen-SASL — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-2967 Related CVEs: CVE-2025-40918 Upstream summary: Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, […]

Read more
Amazon Linux 2 — python-ipaddress — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — python-ipaddress — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2023-2174 Related CVEs: CVE-2020-14422 CVE-2024-4032 Upstream summary: A vulnerability was found in the way the ipaddress python module computes hash values in the IPv4Interface and IPv6Interface classes. This flaw allows […]

Read more
Amazon Linux 2 — python-jinja2 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — python-jinja2 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-2792 Related CVEs: CVE-2025-27516 CVE-2024-56326 CVE-2016-10745 CVE-2024-22195 CVE-2024-34064 Upstream summary: Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the […]

Read more
Amazon Linux 2 — bpftrace — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — bpftrace — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2024-2552 Related CVEs: CVE-2024-2313 Upstream summary: If kernel headers need to be extracted, bpftrace will attempt to load them from a temporary directory. An unprivileged attacker could use this to […]

Read more
Amazon Linux 2 — kernel-livepatch-5.10.240-238.959 — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.240-238.959 — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2025-280 Related CVEs: CVE-2022-50500 CVE-2023-53530 CVE-2025-38527 CVE-2025-39677 CVE-2025-39691 CVE-2025-39730 CVE-2025-39923 Upstream summary: In the Linux kernel, the following vulnerability has been resolved: netdevsim: fix memory leak in nsim_drv_probe() when nsim_dev_resources_register() […]

Read more
Amazon Linux 2 — 389-ds-base — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — 389-ds-base — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-3025 Related CVEs: CVE-2025-4404 CVE-2025-7493 CVE-2025-14905 CVE-2019-14824 CVE-2018-1089 CVE-2017-15135 CVE-2018-1054 CVE-2017-15134  +12 more Upstream summary: A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability […]

Read more
CHAT