Amazon Linux 2023

Amazon Linux 2023 — kernel-livepatch-6.1.94-99.176 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — kernel-livepatch-6.1.94-99.176 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023LIVEPATCH-2024-031 Related CVEs: CVE-2024-41090 CVE-2024-41091 CVE-2024-41087 Upstream summary: kernel: virtio-net: tap: mlx5_core short frame denial of service (CVE-2024-41090) kernel: virtio-net: tun: mlx5_core short frame denial of service (CVE-2024-41091) Table of […]

Read more
Amazon Linux 2023 — kernel-livepatch-6.1.96-102.177 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — kernel-livepatch-6.1.96-102.177 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023LIVEPATCH-2024-029 Related CVEs: CVE-2024-41090 CVE-2024-41091 CVE-2024-41087 Upstream summary: kernel: virtio-net: tap: mlx5_core short frame denial of service (CVE-2024-41090) kernel: virtio-net: tun: mlx5_core short frame denial of service (CVE-2024-41091) Table of […]

Read more
Amazon Linux 2023 — kernel-livepatch-6.1.97-104.177 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — kernel-livepatch-6.1.97-104.177 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023LIVEPATCH-2024-030 Related CVEs: CVE-2024-41090 CVE-2024-41091 Upstream summary: kernel: virtio-net: tap: mlx5_core short frame denial of service (CVE-2024-41090) kernel: virtio-net: tun: mlx5_core short frame denial of service (CVE-2024-41091) Table of contents […]

Read more
Amazon Linux 2023 — python-virtualenv — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — python-virtualenv — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2025-831 Related CVEs: CVE-2024-53899 CVE-2024-9287 Upstream summary: virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. […]

Read more
Amazon Linux 2023 — iperf3 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — iperf3 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2025-812 Related CVEs: CVE-2024-53580 CVE-2023-38403 CVE-2025-54349 CVE-2025-54350 Upstream summary: iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function. (CVE-2024-53580) Table of contents Symptom & Impact Environment […]

Read more
Amazon Linux 2023 — rsync — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — rsync — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2025-801 Related CVEs: CVE-2024-12085 CVE-2024-12086 CVE-2024-12087 CVE-2024-12088 CVE-2024-12747 CVE-2018-25032 CVE-2022-29154 CVE-2022-37434  +1 more Upstream summary: A flaw was found in the rsync daemon which could be triggered when rsync compares […]

Read more
Amazon Linux 2023 — jackson-databind — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — jackson-databind — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2025-798 Related CVEs: CVE-2022-42004 CVE-2021-46877 Upstream summary: In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply […]

Read more
Amazon Linux 2023 — dotnet6.0 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — dotnet6.0 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2024-776 Related CVEs: CVE-2024-43483 CVE-2024-43484 CVE-2024-43485 CVE-2024-38095 CVE-2024-21409 CVE-2024-20672 CVE-2024-21386 CVE-2024-21404  +12 more Upstream summary: .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability (CVE-2024-43483) .NET, .NET Framework, and […]

Read more
Amazon Linux 2023 — python-waitress — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — python-waitress — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2024-773 Related CVEs: CVE-2024-49768 CVE-2024-49769 Upstream summary: Waitress is a Web Server Gateway Interface server for Python 2 and 3. A remote client may send a request that is exactly […]

Read more
Amazon Linux 2023 — ruby3.2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — ruby3.2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2024-743 Related CVEs: CVE-2024-47220 CVE-2023-28755 CVE-2023-28756 CVE-2025-43857 CVE-2025-6442 CVE-2025-24294 CVE-2025-27221 CVE-2025-25186  +12 more Upstream summary: An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP […]

Read more
CHAT