Amazon Linux

Amazon Linux 2023 — snakeyaml — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — snakeyaml — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2023-375 Related CVEs: CVE-2022-38752 CVE-2022-41854 CVE-2022-38750 Upstream summary: Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on […]

Read more
Amazon Linux 2 — kernel-livepatch-5.10.184-175.731 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.184-175.731 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2023-142 Related CVEs: CVE-2023-3609 CVE-2023-3776 Upstream summary: A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will […]

Read more
Amazon Linux 2 — libsass — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — libsass — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2MATE-DESKTOP1.X-2024-004 Related CVEs: CVE-2022-26592 CVE-2022-43357 CVE-2022-43358 Upstream summary: Stack Overflow vulnerability in libsass 3.6.5 via the CompoundSelector::has_real_parent_ref function. (CVE-2022-26592) Stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g210218, which […]

Read more
Amazon Linux 2 — poppler — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — poppler — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2023-2281 Related CVEs: CVE-2020-36023 CVE-2020-36024 CVE-2022-38349 CVE-2020-23804 CVE-2018-20662 CVE-2020-18839 CVE-2022-37050 CVE-2022-27337  +12 more Upstream summary: An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a […]

Read more
Amazon Linux 2023 — lynx — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — lynx — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2024-535 Related CVEs: CVE-2021-38165 Upstream summary: Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI […]

Read more
Amazon Linux 2023 — rsyslog — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — rsyslog — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2023-001 Related CVEs: CVE-2014-3634 CVE-2022-24903 Upstream summary: A flaw was found in the way rsyslog handled invalid log message priority values. In certain configurations, a local attacker, or a remote […]

Read more
Amazon Linux 2 — kernel-livepatch-5.10.130-118.517 — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.130-118.517 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2022-092 Related CVEs: CVE-2022-2585 Upstream summary: A use-after-free flaw was found in the Linux kernel's POSIX CPU timers functionality in the way a user creates and then deletes the timer […]

Read more
Amazon Linux 2 — sysstat — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — sysstat — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2023-2068 Related CVEs: CVE-2022-39377 CVE-2023-33204 Upstream summary: sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix for CVE-2022-39377. […]

Read more
Amazon Linux 2 — qt — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — qt — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2020-1574 Related CVEs: CVE-2020-17507 CVE-2023-38197 CVE-2023-32573 CVE-2023-34410 CVE-2018-15518 CVE-2018-19869 CVE-2018-19870 CVE-2018-19871  +2 more Upstream summary: An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body […]

Read more
CHAT