Amazon Linux 2 — cpio — multiple vulnerabilities (3 CVEs) — patch and remediation guide
🟠 High ⏱ 15–60 min Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read • Source: Amazon Linux advisory ALAS2-2024-2489 Related CVEs: CVE-2015-1197 CVE-2021-38185 CVE-2019-14866 Upstream summary: cpio 2.11, when using the –no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file […]