Amazon Linux 2

Amazon Linux 2 — gtk3 — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — gtk3 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2024-2602 Related CVEs: CVE-2024-6655 Upstream summary: gtk3: gtk2: Library injection from CWD (CVE-2024-6655) Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution […]

Read more
Amazon Linux 2 — kernel-livepatch-4.14.348-265.565 — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-4.14.348-265.565 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2024-189 Related CVEs: CVE-2024-39480 Upstream summary: In the Linux kernel, the following vulnerability has been resolved: kdb: Fix buffer overflow during tab-complete (CVE-2024-39480) Table of contents Symptom & Impact Environment […]

Read more
Amazon Linux 2 — gstreamer-plugins-bad-free — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — gstreamer-plugins-bad-free — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-2972 Related CVEs: CVE-2023-40474 Upstream summary: Integer overflow leading to heap overwrite in MXF file handling with uncompressed video NOTE: https://gstreamer.freedesktop.org/security/sa-2023-0006.html NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/5362 NOTE: Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/ce17e968e4cf900d28ca5b46f6e095febc42b4f0 (CVE-2023-40474) Table of […]

Read more
Amazon Linux 2 — gstreamer1 — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — gstreamer1 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-2746 Related CVEs: CVE-2024-47606 Upstream summary: GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in the function qtdemux_parse_theora_extension within qtdemux.c. The vulnerability […]

Read more
Amazon Linux 2 — cloud-init — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — cloud-init — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-2926 Related CVEs: CVE-2024-6174 CVE-2023-1786 CVE-2021-3429 CVE-2019-0816 CVE-2018-10896 CVE-2020-8631 CVE-2020-8632 Upstream summary: When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP […]

Read more
Amazon Linux 2 — booth — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — booth — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2024-2575 Related CVEs: CVE-2024-3049 CVE-2022-2553 Upstream summary: A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid […]

Read more
Amazon Linux 2 — kernel-livepatch-5.10.157-139.675 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.157-139.675 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2023-117 Related CVEs: CVE-2023-1078 CVE-2023-26545 CVE-2023-0179 CVE-2022-3623 CVE-2022-4378 Upstream summary: The upstream bug report describes this issue as follows: A flaw found in the Linux Kernel in RDS (Reliable Datagram […]

Read more
Amazon Linux 2 — kernel-livepatch-5.10.162-141.675 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.162-141.675 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2023-121 Related CVEs: CVE-2023-1077 CVE-2023-28466 CVE-2023-1078 CVE-2023-26545 CVE-2023-0179 Upstream summary: kernel: Type confusion in pick_next_rt_entity(), which can result in memory corruption. (CVE-2023-1077) do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through […]

Read more
Amazon Linux 2 — perl-App-cpanminus — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — perl-App-cpanminus — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2024-2697 Related CVEs: CVE-2024-45321 CVE-2020-16154 Upstream summary: The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers. (CVE-2024-45321) Table of contents Symptom […]

Read more
Amazon Linux 2 — kernel-livepatch-5.10.220-209.869 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.220-209.869 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2024-190 Related CVEs: CVE-2024-41087 CVE-2022-48666 CVE-2024-41090 CVE-2024-41091 Upstream summary: In the Linux kernel, the following vulnerability has been resolved: ata: libata-core: Fix double free on error (CVE-2024-41087) Table of contents […]

Read more
CHAT