Amazon Linux 2 — tar — multiple vulnerabilities (3 CVEs) — patch and remediation guide
🟠 High ⏱ 15–60 min Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read • Source: Amazon Linux advisory ALAS2-2023-1994 Related CVEs: CVE-2022-48303 CVE-2019-9923 CVE-2023-39804 Upstream summary: GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to […]